CVE-2008-2030 – F5 Networks FirePass 4100 SSL VPN - 'installControl.php3' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2008-2030
Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en installControl.php3 de F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 y 6.0-6.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de la cadena query. NOTA: el origen de esta información es desconocido; los detalles se han obtenido únicamente de información de terceros. • https://www.exploit-db.com/exploits/31698 http://downloads.securityfocus.com/vulnerabilities/exploits/28902.html http://secunia.com/advisories/29931 http://www.securityfocus.com/bid/28902 https://exchange.xforce.ibmcloud.com/vulnerabilities/42078 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-6704 – F5 Networks FirePass 4100 SSL VPN - 'Download_Plugin.php3' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-6704
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en F5 FirePass 4100 SSL VPN 5.4.1 hasta 5.5.2 y 6.0 hasta 6.0.1, cuando las secuencias pre-logon están activadas, permiten a atacantes remotos inyectar web script o HMTL de su elección a través de la cadena de consulta de (1) my.activation.php3 y (2) my.logon.php3. • https://www.exploit-db.com/exploits/30834 https://www.exploit-db.com/exploits/30833 http://secunia.com/advisories/27904 http://securityreason.com/securityalert/3712 http://www.osvdb.org/38980 http://www.osvdb.org/38981 http://www.procheckup.com/Vulnerability_PR07-14.php http://www.procheckup.com/Vulnerability_PR07-15a.php http://www.securityfocus.com/archive/1/484411/100/0/threaded http://www.securityfocus.com/archive/1/484413/100/0/threaded http://www.securityfocus.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-5979 – F5 FirePass 4100 SSL VPN - 'Download_Plugin.php3' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-5979
Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter. Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en download_plugin.php3 en F5 Firepass 4100 SSL VPN 5.4 hasta la 5.5.2 y 6.0 hasta la 6.0.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro backurl. • https://www.exploit-db.com/exploits/30755 http://osvdb.org/38665 http://secunia.com/advisories/27647 http://securityreason.com/securityalert/3364 http://www.procheckup.com/Vulnerability_PR07-13.php http://www.securityfocus.com/archive/1/483601/100/0/threaded http://www.securityfocus.com/bid/26412 http://www.securitytracker.com/id?1018937 http://www.vupen.com/english/advisories/2007/3847 https://exchange.xforce.ibmcloud.com/vulnerabilities/38439 https://support.f5.com/kb/en- • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2006-3550
https://notcve.org/view.php?id=CVE-2006-3550
Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends." Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en F5 Networks FirePass 4100 5.x permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de "campos de formulario escribibles y ocultos" no especificados incluyendo "interfaces frontales de autenticación". • http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047635.html http://securityreason.com/securityalert/1237 http://securitytracker.com/id?1016431 http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2352 http://www.securityfocus.com/archive/1/439033/100/0/threaded http://www.securityfocus.com/bid/18799 http://www.vupen.com/english/advisories/2006/2678 https://exchange.xforce.ibmcloud.com/vulnerabilities/27547 •
CVE-2006-1357 – F5 Firepass 4100 SSL VPN - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2006-1357
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. • https://www.exploit-db.com/exploits/27452 http://secunia.com/advisories/19337 http://securityreason.com/securityalert/611 http://securitytracker.com/id?1015798 http://www.securityfocus.com/archive/1/428318/100/0/threaded http://www.securityfocus.com/bid/17175 http://www.vupen.com/english/advisories/2006/1036 https://exchange.xforce.ibmcloud.com/vulnerabilities/25393 •