Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the sql_matchscope parameter in vdesk/admincon/index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
F5 FirePass SSL VPN 多个跨站脚本漏洞
Vulnerability Description
F5 FirePass SSL VPN设备允许用户安全地连接到关键业务应用设备上。 F5 FirePass SSL VPN设备对通过Portal Access所提交的Web请求执行基本的过滤,Content Inspection功能是通过Web管理接口配置和自定义的,而这个Web管理界面的/vdesk/admincon/webyfiers.php文件没有正确地验证css_exceptions参数输入,/vdesk/admincon/index.php文件没有正确地验证sql_matchscope参数输入。
CVSS Information
N/A
Vulnerability Type
N/A