F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
BID:26659
Info
F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
| Bugtraq ID: | 26659 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6704 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2007 12:00AM |
| Updated: | Apr 16 2015 06:08PM |
| Credit: | Richard Brain of Procheckup Ltd is credited with the discovery of this vulnerability. |
| Vulnerable: |
F5 FirePass 4100 5.4.2 F5 FirePass 4100 0 F5 FirePass 6.0.1 F5 FirePass 5.5.2 F5 FirePass 5.4.1 F5 FirePass 6.0 F5 FirePass |
| Not Vulnerable: | |
Discussion
F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
F5 Networks FirePass 4100 SSL VPN devices are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
F5 Networks FirePass 4100 SSL VPNs running these firmware versions are vulnerable:
5.4.1 through 5.5.2
6.0
6.0.1
F5 Networks FirePass 4100 SSL VPN devices are prone to a cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker to steal cookie-based authentication credentials and to launch other attacks.
F5 Networks FirePass 4100 SSL VPNs running these firmware versions are vulnerable:
5.4.1 through 5.5.2
6.0
6.0.1
Exploit / POC
F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept code is available:
Attackers can exploit this issue via a browser.
The following proof-of-concept code is available:
Solution / Fix
F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
Solution:
The vendor issued a support document regarding this issue. Users of affected devices should contact the vendor for information on the availability of fixes. Please see the references for more information.
Solution:
The vendor issued a support document regarding this issue. Users of affected devices should contact the vendor for information on the availability of fixes. Please see the references for more information.
References
F5 Networks FirePass 4100 SSL VPN My.Logon.PHP3 Cross-Site Scripting Vulnerability
References:
References:
- PR07-15: Cross-site Scripting (XSS) / HTML injection on F5 FirePass 4100 SSL VPN (ProCheckUp)
- SOL7923 (F5)
- Vendor Homepage (F5)
- PR07-15: Cross-site Scripting (XSS) / HTML injection on F5 FirePass 4100 SSL V ([email protected])
- PR07-15: Cross-site Scripting (XSS) / HTML injection on F5 FirePass 4100 SSL VPN ("Ricardo Martins - Chief Security Officers"
)