Cross-Site Scripting Vulnerability in F5 Firepass 4100 SSL VPN
CVE-2006-1357

Currently unrated

Key Information:

Vendor
F5
Vendor
CVE Published:
22 March 2006

Summary

A cross-site scripting (XSS) vulnerability exists in the my.support.php3 file of the F5 Firepass 4100 SSL VPN version 5.4.2. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the 's' parameter. If exploited, this vulnerability can lead to unauthorized actions taken on behalf of users or leakage of sensitive information.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.