PR07-14: Cross-site Scripting (XSS) / HTML injection on F5 FirePass 4100
SSL VPN 'my.activation.php3' server-side script
Date Found: 19th June 2007
Successfully tested on: version 5.5.2
F5 Networks has confirmed the following versions to be vulnerable:
FirePass versions 5.4.1 - 5.5.2
FirePass versions 6.0 - 6.0.1
Description:
F5 Networks FirePass 4100 SSL VPN is vulnerable to XSS within the
"my.activation.php3" server-side script.
No authentication is required to exploit this vulnerability.
Consequences:
An attacker may be able to cause execution of malicious scripting code in
the browser of a user who visits a specially-crafted URL to an F5 Firepass
device, or visits a malicious page that makes a request to such URL. Such
code would run within the security context of the target domain.
This type of attack can result in non-persistent defacement of the target
site, or the redirection of confidential information (i.e. admin session
IDs) to unauthorised third parties.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.