F5 WebSafe Alert Server CVE-2016-5235 Cross Site Scripting Vulnerability
BID:109041
Info
F5 WebSafe Alert Server CVE-2016-5235 Cross Site Scripting Vulnerability
| Bugtraq ID: | 109041 |
| Class: | Input Validation Error |
| CVE: |
CVE-2016-5235 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2016 12:00AM |
| Updated: | Jul 01 2016 12:00AM |
| Credit: | Blazej Wincenciak and Krzysztof Wegrzynek of Prevenity. |
| Vulnerable: |
F5 WebSafe Alert Server 3.9.5 F5 WebSafe Alert Server 3.9 F5 WebSafe Alert Server 1.0 |
| Not Vulnerable: |
F5 WebSafe Alert Server 4.0 |
Discussion
F5 WebSafe Alert Server CVE-2016-5235 Cross Site Scripting Vulnerability
F5 WebSafe Alert Server is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to WebSafe Alert Server 3.9.x are vulnerable.
F5 WebSafe Alert Server is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to WebSafe Alert Server 3.9.x are vulnerable.
Exploit / POC
F5 WebSafe Alert Server CVE-2016-5235 Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
References
F5 WebSafe Alert Server CVE-2016-5235 Cross Site Scripting Vulnerability
References:
References: