Cross-Site Scripting Vulnerability in F5 Firepass 4100 SSL VPN
CVE-2006-1357
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in the my.support.php3 file of the F5 Firepass 4100 SSL VPN version 5.4.2. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the 's' parameter. If exploited, this vulnerability can lead to unauthorized actions taken on behalf of users or leakage of sensitive information.
References
EPSS Score
6% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved