ID

VAR-200903-0109


CVE

CVE-2008-6474


TITLE

F5 BIG-IP Any in the management interface of Perl Code injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2009-001448

DESCRIPTION

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection. F5 BIG-IP Web Management Interface is prone to a remote code-injection vulnerability because the application fails to properly sanitize user-supplied input. Exploiting this issue allows attackers to execute arbitrary code with the privileges of the user running the affected application. This issue affects F5 BIG-IP 9.4.3; other versions may also be affected. F5 BIG-IP is an all-in-one network device integrated with network traffic management, application security management, load balancing and other functions from F5 Corporation of the United States. The vulnerability is caused by using Perl EP3 with templates similar to the following without escaping the single quotes in NEW_VALUE: $val=&\'\'NEW_VALUE&\'\'; ​​For example, the SNMP community string configuration accepts The following value is an SNMP request: \"none\'\'.`touch /etc/foo`.\'\'\" An attacker can create a specially crafted URL link that can inject an HTTP GET request through cross-site scripting in BIG-IP Make any changes on the device

Trust: 1.98

sources: NVD: CVE-2008-6474 // JVNDB: JVNDB-2009-001448 // BID: 28639 // VULHUB: VHN-36599

AFFECTED PRODUCTS

vendor:f5model:tmosscope:eqversion:9.4.3

Trust: 1.6

vendor:f5model:big-ipscope:eqversion:9.4.3

Trust: 1.4

vendor:f5model:big-ip web management interfacescope:eqversion:9.4.3

Trust: 0.3

vendor:f5model:big-ip web management interfacescope:neversion:9.4.5

Trust: 0.3

sources: BID: 28639 // JVNDB: JVNDB-2009-001448 // CNNVD: CNNVD-200903-268 // NVD: CVE-2008-6474

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-6474
value: HIGH

Trust: 1.0

NVD: CVE-2008-6474
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200903-268
value: CRITICAL

Trust: 0.6

VULHUB: VHN-36599
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2008-6474
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-36599
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-36599 // JVNDB: JVNDB-2009-001448 // CNNVD: CNNVD-200903-268 // NVD: CVE-2008-6474

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.9

sources: VULHUB: VHN-36599 // JVNDB: JVNDB-2009-001448 // NVD: CVE-2008-6474

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200903-268

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-200903-268

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001448

PATCH

title:Top Pageurl:http://www.f5networks.co.jp/

Trust: 0.8

sources: JVNDB: JVNDB-2009-001448

EXTERNAL IDS

db:NVDid:CVE-2008-6474

Trust: 2.8

db:BIDid:28639

Trust: 2.0

db:OSVDBid:51116

Trust: 1.7

db:JVNDBid:JVNDB-2009-001448

Trust: 0.8

db:CNNVDid:CNNVD-200903-268

Trust: 0.7

db:XFid:5

Trust: 0.6

db:XFid:49308

Trust: 0.6

db:BUGTRAQid:20080405 F5 BIG-IP MANAGEMENT INTERFACE PERL INJECTION

Trust: 0.6

db:VULHUBid:VHN-36599

Trust: 0.1

sources: VULHUB: VHN-36599 // BID: 28639 // JVNDB: JVNDB-2009-001448 // CNNVD: CNNVD-200903-268 // NVD: CVE-2008-6474

REFERENCES

url:http://www.securityfocus.com/bid/28639

Trust: 1.7

url:http://osvdb.org/51116

Trust: 1.7

url:http://www.securityfocus.com/archive/1/490496/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/49308

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-6474

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-6474

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/49308

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/490496/100/0/threaded

Trust: 0.6

url:http://www.f5.com/products/big-ip/

Trust: 0.3

url:/archive/1/490496

Trust: 0.3

sources: VULHUB: VHN-36599 // BID: 28639 // JVNDB: JVNDB-2009-001448 // CNNVD: CNNVD-200903-268 // NVD: CVE-2008-6474

CREDITS

nnposter nnposter@disclosed.not

Trust: 0.6

sources: CNNVD: CNNVD-200903-268

SOURCES

db:VULHUBid:VHN-36599
db:BIDid:28639
db:JVNDBid:JVNDB-2009-001448
db:CNNVDid:CNNVD-200903-268
db:NVDid:CVE-2008-6474

LAST UPDATE DATE

2024-11-23T19:52:40.232000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-36599date:2018-10-30T00:00:00
db:BIDid:28639date:2015-05-07T17:30:00
db:JVNDBid:JVNDB-2009-001448date:2009-06-30T00:00:00
db:CNNVDid:CNNVD-200903-268date:2009-03-26T00:00:00
db:NVDid:CVE-2008-6474date:2024-11-21T00:56:37.770

SOURCES RELEASE DATE

db:VULHUBid:VHN-36599date:2009-03-16T00:00:00
db:BIDid:28639date:2008-04-05T00:00:00
db:JVNDBid:JVNDB-2009-001448date:2009-06-30T00:00:00
db:CNNVDid:CNNVD-200903-268date:2008-04-05T00:00:00
db:NVDid:CVE-2008-6474date:2009-03-16T16:30:00.313