Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an <FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php. NOTE: it is possible that this candidate overlaps CVE-2006-3550.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
F5 Firepass 'my.logon.php3' 多个跨站攻击漏洞
Vulnerability Description
F5 FirePass SSL VPN中存在多个跨站攻击漏洞。远程攻击者可以借助提交到my.logon.php3的(1)xcho参数,per操作中提交到vdesk/admincon/index.php的(2)topblue,(3)midblue,(4)wtopblue和特定的其他顾客颜色参数,到vdesk/admincon/index.php的(5)h321,(6)h311,(7)h312和特定的其他前门顾客正文颜色参数,bro操作中到vdesk/admincon/index.php的(8)ua参数,到w
CVSS Information
N/A
Vulnerability Type
N/A