Cross-Site Scripting Vulnerabilities in F5 BIG-IP Web Management Interface
CVE-2008-0265

Currently unrated

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
15 January 2008

Summary

The F5 BIG-IP web management interface prior to version 9.4.3 is susceptible to multiple cross-site scripting (XSS) vulnerabilities. Attackers can exploit these flaws by injecting arbitrary scripts or HTML code through the SearchString parameter. This can affect various pages including list_system.jsp, list_pktfilter.jsp, list_ltm.jsp, resources_audit.jsp, and list_asm.jsp, potentially allowing unauthorized execution of malicious scripts within the context of a user's session.

References

EPSS Score

11% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.