Cross-Site Scripting Vulnerability in F5 BIG-IP Web Management Interface
CVE-2008-1503

Currently unrated

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
25 March 2008

Summary

The F5 BIG-IP web management interface version 9.4.3 is vulnerable to a Cross-site Scripting (XSS) attack that allows remote attackers to inject arbitrary web scripts or HTML. This vulnerability occurs through the name of a node object, and the sysContact or sysLocation SNMP configuration fields. Compromise might be exacerbated due to potential Cross-site Request Forgery (CSRF) vulnerabilities, which could facilitate unauthorized actions through the affected web management interface.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.