ID

VAR-200803-0496


CVE

CVE-2008-1503


TITLE

F5 BIG-IP of Web Management interface cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2008-002887

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a node object, or the (2) sysContact or (3) sysLocation SNMP configuration field, aka "Audit Log XSS." NOTE: these issues might be resultant from cross-site request forgery (CSRF) vulnerabilities. (1) Node object name (2) sysContact SNMP Setting field (3) sysLocation SNMP Setting field. F5 Big-IP is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible. F5 Big-IP 9.4.3 is vulnerable; other versions may also be affected. F5 BIG-IP is an all-in-one network device integrated with network traffic management, application security management, load balancing and other functions from F5 Corporation of the United States. Log entries are output without HTML encoding, which allows attackers to create log entries with embedded scripts that execute malicious scripts if an administrator views the audit logs. One possible attack is to create a node object with a script embedded in the node name. Creating this node will fail due to unsupported characters, but will still create an audit log; it is also possible to create a specially crafted URL link that will Generate log entries with embedded HTTP GET requests, so this vulnerability can be exploited remotely

Trust: 1.98

sources: NVD: CVE-2008-1503 // JVNDB: JVNDB-2008-002887 // BID: 28416 // VULHUB: VHN-31628

AFFECTED PRODUCTS

vendor:f5model:big-ipscope:eqversion:9.4.3

Trust: 1.7

vendor:f5model:tmosscope:eqversion:9.4.3

Trust: 1.6

sources: BID: 28416 // JVNDB: JVNDB-2008-002887 // CNNVD: CNNVD-200803-415 // NVD: CVE-2008-1503

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-1503
value: MEDIUM

Trust: 1.0

NVD: CVE-2008-1503
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200803-415
value: MEDIUM

Trust: 0.6

VULHUB: VHN-31628
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2008-1503
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-31628
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-31628 // JVNDB: JVNDB-2008-002887 // CNNVD: CNNVD-200803-415 // NVD: CVE-2008-1503

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-31628 // JVNDB: JVNDB-2008-002887 // NVD: CVE-2008-1503

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200803-415

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200803-415

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-002887

PATCH

title:Top Pageurl:http://www.f5.com/products/big-ip/

Trust: 0.8

sources: JVNDB: JVNDB-2008-002887

EXTERNAL IDS

db:NVDid:CVE-2008-1503

Trust: 2.8

db:BIDid:28416

Trust: 2.0

db:SREASONid:3778

Trust: 1.7

db:JVNDBid:JVNDB-2008-002887

Trust: 0.8

db:CNNVDid:CNNVD-200803-415

Trust: 0.7

db:XFid:41440

Trust: 0.6

db:XFid:5

Trust: 0.6

db:BUGTRAQid:20080323 F5 BIG-IP WEB MANAGEMENT AUDIT LOG XSS

Trust: 0.6

db:VULHUBid:VHN-31628

Trust: 0.1

sources: VULHUB: VHN-31628 // BID: 28416 // JVNDB: JVNDB-2008-002887 // CNNVD: CNNVD-200803-415 // NVD: CVE-2008-1503

REFERENCES

url:http://www.securityfocus.com/bid/28416

Trust: 1.7

url:http://securityreason.com/securityalert/3778

Trust: 1.7

url:http://www.securityfocus.com/archive/1/489991/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/41440

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-1503

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-1503

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/41440

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/489991/100/0/threaded

Trust: 0.6

url:http://www.f5.com/products/big-ip/

Trust: 0.3

url:/archive/1/489991

Trust: 0.3

sources: VULHUB: VHN-31628 // BID: 28416 // JVNDB: JVNDB-2008-002887 // CNNVD: CNNVD-200803-415 // NVD: CVE-2008-1503

CREDITS

nnposter nnposter@disclosed.not

Trust: 0.6

sources: CNNVD: CNNVD-200803-415

SOURCES

db:VULHUBid:VHN-31628
db:BIDid:28416
db:JVNDBid:JVNDB-2008-002887
db:CNNVDid:CNNVD-200803-415
db:NVDid:CVE-2008-1503

LAST UPDATE DATE

2024-11-23T21:31:38.942000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-31628date:2018-10-30T00:00:00
db:BIDid:28416date:2015-05-07T17:32:00
db:JVNDBid:JVNDB-2008-002887date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200803-415date:2008-09-05T00:00:00
db:NVDid:CVE-2008-1503date:2024-11-21T00:44:41.527

SOURCES RELEASE DATE

db:VULHUBid:VHN-31628date:2008-03-25T00:00:00
db:BIDid:28416date:2008-03-24T00:00:00
db:JVNDBid:JVNDB-2008-002887date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200803-415date:2008-03-25T00:00:00
db:NVDid:CVE-2008-1503date:2008-03-25T19:44:00