PT-2007-6906 · F5 · F5 Firepass 4100 Ssl Vpn

Adrian Pastor

+1

·

Published

2007-11-15

·

Updated

2018-10-15

·

CVE-2007-5979

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions F5 Firepass 4100 SSL VPN versions 5.4 through 5.5.2 F5 Firepass 4100 SSL VPN versions 6.0 through 6.0.1
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the backurl parameter in the download plugin.php3 file.
Recommendations For versions 5.4 through 5.5.2, avoid using the backurl parameter in the download plugin.php3 file until a fix is available. For versions 6.0 through 6.0.1, restrict access to the download plugin.php3 file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5979

Affected Products

F5 Firepass 4100 Ssl Vpn