ID

VAR-E-200803-0399


CVE

cve_id:CVE-2008-0539

Trust: 0.3

sources: BID: 28151

EDB ID

31364


TITLE

F5 BIG-IP 9.4.3 - Web Management Interface Console HTML Injection - Hardware remote Exploit

Trust: 0.6

sources: EXPLOIT-DB: 31364

DESCRIPTION

F5 BIG-IP 9.4.3 - Web Management Interface Console HTML Injection.. remote exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 31364

AFFECTED PRODUCTS

vendor:f5model:big-ipscope:eqversion:9.4.3

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:9.4.3

Trust: 0.3

sources: BID: 28151 // EXPLOIT-DB: 31364 // EDBNET: 52952

EXPLOIT

source: https://www.securityfocus.com/bid/28151/info

F5 BIG-IP Web Management Interface is prone to a HTML-injection vulnerability because the web management interface fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected device. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

The vulnerability affects F5 BIG-IP 9.4.3; other versions may be also affected.

https://(target)/dms/policy/rep_request.php?report_type=%22%3E%3Cbody+onload=alert(%26quot%3BXSS%26quot%3B)%3E%3Cfoo+

Trust: 1.0

sources: EXPLOIT-DB: 31364

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 31364

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 31364

TYPE

Web Management Interface Console HTML Injection

Trust: 1.0

sources: EXPLOIT-DB: 31364

CREDITS

nnposter

Trust: 0.6

sources: EXPLOIT-DB: 31364

EXTERNAL IDS

db:EXPLOIT-DBid:31364

Trust: 1.9

db:BIDid:28151

Trust: 1.9

db:EDBNETid:52952

Trust: 0.6

db:NVDid:CVE-2008-0539

Trust: 0.3

sources: BID: 28151 // EXPLOIT-DB: 31364 // EDBNET: 52952

REFERENCES

url:https://www.securityfocus.com/bid/28151/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/31364/

Trust: 0.6

url:https://www.exploit-db.com/exploits/31364

Trust: 0.3

url:http://www.f5.com/f5products/bigip/

Trust: 0.3

sources: BID: 28151 // EXPLOIT-DB: 31364 // EDBNET: 52952

SOURCES

db:BIDid:28151
db:EXPLOIT-DBid:31364
db:EDBNETid:52952

LAST UPDATE DATE

2022-07-27T09:13:31.194000+00:00


SOURCES UPDATE DATE

db:BIDid:28151date:2015-05-07T17:32:00

SOURCES RELEASE DATE

db:BIDid:28151date:2008-03-08T00:00:00
db:EXPLOIT-DBid:31364date:2008-03-08T00:00:00
db:EDBNETid:52952date:2008-03-08T00:00:00