CVE Database
/

CVE-2007-0186

Back to search

CVE-2007-0186

Published: Jan 11, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an <FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php. NOTE: it is possible that this candidate overlaps CVE-2006-3550.

VendorProductVersions

n/a

n/a

affected
n/a

References

23627
third-party-advisory
x_refsource_SECUNIA
32738
vdb-entry
x_refsource_OSVDB
32739
vdb-entry
x_refsource_OSVDB
23643
third-party-advisory
x_refsource_SECUNIA
32737
vdb-entry
x_refsource_OSVDB
32743
vdb-entry
x_refsource_OSVDB
32740
vdb-entry
x_refsource_OSVDB
32741
vdb-entry
x_refsource_OSVDB
32742
vdb-entry
x_refsource_OSVDB
21957
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now