ID

VAR-E-200801-0221


CVE

cve_id:CVE-2008-0265

Trust: 1.9

sources: BID: 27272 // EXPLOIT-DB: 31024 // EDBNET: 52631

EDB ID

31024


TITLE

F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 31024

DESCRIPTION

F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities. CVE-2008-0265CVE-40345 . remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 31024

AFFECTED PRODUCTS

vendor:f5model:big-ipscope:eqversion:9.4.3

Trust: 1.3

vendor:f5model:big-ipscope:lteversion:<=9.4.3

Trust: 0.6

vendor:f5model:wanjetscope:eqversion:5.0

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:1.4.1

Trust: 0.3

vendor:f5model:enterprise managerscope:eqversion:1.0

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.3.1

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.2.5

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.2.2

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.1

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0.5

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0.4

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0.3

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0.2

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0.1

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.0

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.4

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.3

Trust: 0.3

vendor:f5model:big-ip buildscope:eqversion:9.2413.1

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:9.2

Trust: 0.3

sources: BID: 27272 // EXPLOIT-DB: 31024 // EDBNET: 52631

EXPLOIT

source: https://www.securityfocus.com/bid/27272/info

F5 BIG-IP is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

BIG-IP firmware version 9.4.3 is vulnerable; other versions may also be affected.

https://www.example.com?SearchString=%22%20type=%22hidden%22%3E%3Cscript%3Ealert(%22list-xss%22)%3C/script%3E%3Cinput%20type=%22hidden%22%20value=%22

Trust: 1.0

sources: EXPLOIT-DB: 31024

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 31024

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 31024

TYPE

'SearchString' Multiple Cross-Site Scripting Vulnerabilities

Trust: 1.6

sources: EXPLOIT-DB: 31024 // EDBNET: 52631

CREDITS

nnposter

Trust: 0.6

sources: EXPLOIT-DB: 31024

EXTERNAL IDS

db:EXPLOIT-DBid:31024

Trust: 1.9

db:NVDid:CVE-2008-0265

Trust: 1.9

db:BIDid:27272

Trust: 1.9

db:EDBNETid:52631

Trust: 0.6

sources: BID: 27272 // EXPLOIT-DB: 31024 // EDBNET: 52631

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2008-0265

Trust: 1.6

url:https://www.securityfocus.com/bid/27272/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/31024/

Trust: 0.6

url:http://www.f5.com/f5products/bigip/

Trust: 0.3

url:https://www.exploit-db.com/exploits/31024

Trust: 0.3

url:https://support.f5.com/kb/en-us/solutions/public/8000/200/sol8280.html

Trust: 0.3

sources: BID: 27272 // EXPLOIT-DB: 31024 // EDBNET: 52631

SOURCES

db:BIDid:27272
db:EXPLOIT-DBid:31024
db:EDBNETid:52631

LAST UPDATE DATE

2022-07-27T09:46:12.994000+00:00


SOURCES UPDATE DATE

db:BIDid:27272date:2008-01-23T03:38:00

SOURCES RELEASE DATE

db:BIDid:27272date:2008-01-14T00:00:00
db:EXPLOIT-DBid:31024date:2008-01-14T00:00:00
db:EDBNETid:52631date:2008-01-14T00:00:00