F5 FirePass Remote SQL Injection Vulnerability
BID:56175
Info
F5 FirePass Remote SQL Injection Vulnerability
| Bugtraq ID: | 56175 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2012 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Aung Khant, Tal Zeltzer |
| Vulnerable: |
F5 FirePass 6.0.3 F5 FirePass 6.0.2 F5 FirePass 6.0.1 F5 FirePass 7.0 F5 FirePass 6.1 F5 FirePass 6.0.2.3 |
| Not Vulnerable: | |
Discussion
F5 FirePass Remote SQL Injection Vulnerability
FirePass is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to FirePass 7.0.0 HF-70-7 and 6.1.0 HF-610-9 are vulnerable.
FirePass is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to FirePass 7.0.0 HF-70-7 and 6.1.0 HF-610-9 are vulnerable.
Exploit / POC
F5 FirePass Remote SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
F5 FirePass Remote SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
F5 FirePass Remote SQL Injection Vulnerability
References:
References: