XSS Vulnerability in F5 FirePass SSL VPN Product
CVE-2008-2030
Currently unrated
What is CVE-2008-2030?
A cross-site scripting vulnerability exists in the installControl.php3 file of F5 FirePass 4100 SSL VPN, impacting versions 5.4.2 to 6.2. This flaw enables remote attackers to inject arbitrary web scripts or HTML into the application via the query string. If exploited, this vulnerability could allow attackers to manipulate user data or potentially escalate their privileges within a compromised session.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.