PT-2012-3528 · F5 · F5 Firepass
Christoph Schwarz
·
Publicado
2012-04-04
·
Atualizado
2018-01-06
·
CVE-2012-1777
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F5 FirePass versions 6.0.0 through 6.1.0
F5 FirePass versions 7.0.0
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
state parameter in the my.activation.php3 file.Recommendations
For F5 FirePass versions 6.0.0 through 6.1.0, update to a version that is not affected by this issue.
For F5 FirePass version 7.0.0, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the my.activation.php3 file until a patch is available.
Avoid using the
state parameter in the affected file until the issue is resolved.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
F5 Firepass