CVE-2008-2637
published 2008-06-10CVE-2008-2637: Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
1.82%
76.3th percentile
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the sql_matchscope parameter in vdesk/admincon/index.php.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | firepass_ssl_vpn | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
F5 FirePass 6.0.2.3 - '/vdesk/admincon/webyfiers.php?css_exceptions' Cross-Site Scripting
exploitdb·2008-06-05
CVE-2008-2637 F5 FirePass 6.0.2.3 - '/vdesk/admincon/webyfiers.php?css_exceptions' Cross-Site Scripting
F5 FirePass 6.0.2.3 - '/vdesk/admincon/webyfiers.php?css_exceptions' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/29574/info
F5 FirePass SSL VPN is prone to multiple cross-site request-forgery vulnerabilities because it fails to adequately sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to execute arbitrary actions in the context of the affected application.
FirePass 6.0.2 hotfix 3 is vulnerable; other versions may also be affected.
https://www.example.com/vdesk/admincon/webyfiers.php?a=css&click=1&css_exceptions=%22+onfocus%3Dalert%28%26quot%3BXSS1%26quot%3B%29+foo%3D%22&save_css_exceptions=Update
Exploit-DB
F5 FirePass 6.0.2.3 - '/vdesk/admincon/index.php?sql_matchscope' Cross-Site Scripting
exploitdb·2008-06-05
CVE-2008-2637 F5 FirePass 6.0.2.3 - '/vdesk/admincon/index.php?sql_matchscope' Cross-Site Scripting
F5 FirePass 6.0.2.3 - '/vdesk/admincon/index.php?sql_matchscope' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/29574/info
F5 FirePass SSL VPN is prone to multiple cross-site request-forgery vulnerabilities because it fails to adequately sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to execute arbitrary actions in the context of the affected application.
FirePass 6.0.2 hotfix 3 is vulnerable; other versions may also be affected.
https://www.example.com/vdesk/admincon/index.php?a=css&sub=sql&sql_matchscope=%22+onfocus%3Dalert%28%26quot%3BXSS2%26quot%3B%29+foo%3D%22&save_sql_matchscope=Update
No writeups or analysis indexed.
http://secunia.com/advisories/30550http://securityreason.com/securityalert/3931http://www.securityfocus.com/archive/1/493149/100/0/threadedhttp://www.securityfocus.com/bid/29574http://www.securitytracker.com/id?1020205http://www.vupen.com/english/advisories/2008/1765/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42884http://secunia.com/advisories/30550http://securityreason.com/securityalert/3931http://www.securityfocus.com/archive/1/493149/100/0/threadedhttp://www.securityfocus.com/bid/29574http://www.securitytracker.com/id?1020205http://www.vupen.com/english/advisories/2008/1765/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42884
2008-06-10
Published