CVE-2009-2119

Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:f5:firepass_ssl_vpn:5.5:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:5.5.1:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:5.5.2:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:6.0:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:6.0.1:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:6.0.2:*:*:*:*:*:*:*
cpe:2.3:h:f5:firepass_ssl_vpn:6.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://osvdb.org/55040 - () http://osvdb.org/55040 -
References () http://secunia.com/advisories/35418 - Vendor Advisory () http://secunia.com/advisories/35418 - Vendor Advisory
References () http://secunia.com/advisories/35426 - Vendor Advisory () http://secunia.com/advisories/35426 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/504232/100/0/threaded - () http://www.securityfocus.com/archive/1/504232/100/0/threaded -
References () http://www.securityfocus.com/bid/35312 - () http://www.securityfocus.com/bid/35312 -
References () http://www.securitytracker.com/id?1022387 - Patch () http://www.securitytracker.com/id?1022387 - Patch
References () http://www.vupen.com/english/advisories/2009/1570 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/1570 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/51064 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/51064 -
References () https://www.fox-it.com/nl/nieuws-en-events/nieuws/laatste-nieuws/nieuwsartikel/f5-firepass-cross-site-scripting-vulnerability/106 - Vendor Advisory () https://www.fox-it.com/nl/nieuws-en-events/nieuws/laatste-nieuws/nieuwsartikel/f5-firepass-cross-site-scripting-vulnerability/106 - Vendor Advisory
References () https://www.fox-it.com/uploads/pdf/advisory_xss_f5_firepass.pdf - () https://www.fox-it.com/uploads/pdf/advisory_xss_f5_firepass.pdf -

Information

Published : 2009-06-18 21:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2119

Mitre link : CVE-2009-2119

CVE.ORG link : CVE-2009-2119


JSON object : View

Products Affected

f5

  • firepass_ssl_vpn
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')