| OSVDB ID | Disclosure Date | Title |
|
61520
Description:
F5 Data Manager contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'ViewSatReport.do' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'ext' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-01-05
|
F5 Data Manager ViewSatReport.do ext Parameter Traversal Arbitrary File Access
|
|
46004
Description:
F5 FirePass contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the '/vdesk/admincon/index.php' script not properly sanitizing user-supplied input to the 'sql_matchscope' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-05
|
F5 FirePass /vdesk/admincon/index.php sql_matchscope Parameter XSS
|
|
46003
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the sql_matchscope parameter in vdesk/admincon/index.php.
|
2008-06-05
|
F5 FirePass /vdesk/admincon/webyfiers.php css_exceptions Parameter XSS
|
|
29779
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5 Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
|
2006-10-17
|
F5 FirePass 1000 SSL VPN my.acctab.php3 sid Parameter XSS
|
|
46813
Description:
(Description Provided by CVE) : The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstalled OID branch in HOST-RESOURCES-MIB.
|
2008-07-03
|
F5 FirePass 1200 SSL VPN SNMP HOST-RESOURCES-MIB Traversing DoS
|
|
44611
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-28
|
F5 FirePass 4100 SSL VPN installControl.php3 XSS
|
|
38980
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
|
2007-12-03
|
F5 FirePass 4100 SSL VPN my.activation.php3 URL XSS
|
|
35246
Description:
F5 Firepass 4100 contains a flaw that may allow a malicious user to execute arbitrary shell commands. The issue is triggered due to the 'username' variable in script 'my.activation.php3' does not properly verify user-supplied input. It is possible that the flaw may allow code execution under unspecified circumstances resulting in a loss of integrity.
|
2007-06-04
|
F5 FirePass 4100 SSL VPN my.activation.php3 username Variable Arbitrary Command Injection
|
|
38981
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
|
2007-11-30
|
F5 FirePass 4100 SSL VPN my.logon.php3 URL XSS
|
|
24034
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
|
2006-03-21
|
F5 Firepass 4100 SSL VPN my.support.php3 s Parameter XSS
|
|
28207
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form fields and hidden fields," including "authentication frontends."
|
2006-07-04
|
F5 FirePass 4100 Unspecified Multiple Parameter XSS
|
|
81501
Description:
F5 FirePassF5 FirePass contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by the program not requiring authentication to execute commands, allowing a local attacker to gain escalated.
|
2012-03-28
|
F5 FirePass Command Execution Authentication Weakness Local Privilege Escalation
|
|
32734
Description:
FirePass contains a flaw that may allow a malicious user to bypass web filter restrictions. The issue is triggered when a user submits an IP address in a URL as a dotless, decimal value, which may allow to bypass any 'deny' statements that may have otherwise affected the IP address, resulting in a loss of integrity.
|
2007-01-05
|
F5 FirePass Dotless IP Address URL Restriction Bypass
|
|
32739
Description:
FirePass contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate values included in <FP_DO_NOT_TOUCH> tags upon submission to unspecified scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-05
|
F5 FirePass FP_DO_NOT_TOUCH Tag XSS
|
|
55040
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
|
2009-06-11
|
F5 FirePass Login Page Password Field XSS
|
|
39167
Description:
(Description Provided by CVE) : F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.
|
2007-01-05
|
F5 FirePass Multiple Method URL Restriction Bypass
|
|
86580
Description:
F5 FirePass contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'refreshURL' parameter upon submission to the my.activation.cns.php3 script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-09-04
|
F5 FirePass my.activation.cns.php3 refreshURL Parameter XSS
|
|
32740
Description:
FirePass contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'vhost' variable upon submission to the 'my.activation.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-05
|
F5 FirePass my.activation.php vhost Parameter XSS
|
|
32736
Description:
F5 FirePass contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an invalid login attempt is made in the login page at 'my.activation.php'. If the username exists in the local LDAP user directory, a slightly different error message will be displayed than in the case of a non-existent username. This will enable an attacker to enumerate valid usernames, resulting in a loss of confidentiality.
|
2007-01-05
|
F5 FirePass my.activation.php3 Error Message LDAP Account Enumeration
|
|
80219
Description:
F5 FirePass contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the my.activation.php3 script not properly sanitizing user-supplied input to the 'state' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-14
|
F5 FirePass my.activation.php3 state Parameter SQL Injection
|
|
32737
Description:
FirePass contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'xcho' variable upon submission to the 'my.logon.php3' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-05
|
F5 FirePass my.logon.php3 xcho Parameter XSS
|
|
63076
Description:
Unknown / Incomplete
|
2010-03-17
|
F5 FirePass OpenSSL EVP_VerifyFinal Function DSA Key Validation Weakness
|
|
66300
Description:
Unknown / Incomplete
|
2010-07-14
|
F5 FirePass Pre-Logon Token Handling Workstation Restriction Bypass
|
|
88091
Description:
F5 FirePass SSL VPN contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the CitrixAuth.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'sessionID' parameter. This directory traversal attack would allow the attacker to gain access to arbitrary files.
|
2012-12-04
|
F5 FirePass SSL VPN CitrixAuth.php sessionId Parameter Traversal Arbitrary File Access
|
|
38665
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.
|
2007-11-13
|
F5 Firepass SSL VPN download_plugin.php3 backurl Parameter XSS
|
|
86565
Description:
F5 FirePass SSL VPN contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the 'refreshURL' parameter upon submission to the my.activation.cns.php3 script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|
2012-10-20
|
F5 FirePass SSL VPN my.activation.cns.php3 refreshURL Parameter Arbitrary Site Redirect
|
|
32738
Description:
FirePass contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the variables upon submission to an unspecified script, where it is processed by two JavaScript 'eval()' functions. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-05
|
F5 FirePass Unspecified Double eval() Function XSS
|
|
66299
Description:
Unknown / Incomplete
|
2010-07-14
|
F5 FirePass Unspecified Pre-Logon Page XSS
|
|
86546
Description:
F5 FirePass contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing user-supplied input before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-06-11
|
F5 FirePass Unspecified SQL Injection
|
|
32742
Description:
FirePass contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ua' variable upon submission to the 'vdesk/admincon/index.php' script when the 'bro' action is used. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-05
|
F5 FirePass vdesk/admincon/index.php bro Action ua Parameter XSS
|