CVE-2007-6704: XSS
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
Affected Software
Event History
Frequently Asked Questions
What are the vulnerabilities associated with CVE-2007-6704?
CVE-2007-6704 includes multiple cross-site scripting (XSS) vulnerabilities affecting specific versions of F5 FirePass 4100, allowing remote attackers to inject arbitrary web scripts via query strings.
What versions of F5 FirePass 4100 are affected by CVE-2007-6704?
Versions 5.4.1 to 5.5.2 and 6.0 to 6.0.1 of F5 FirePass 4100 are affected by CVE-2007-6704.
What is the impact of CVE-2007-6704 on the affected systems?
CVE-2007-6704 can enable attackers to execute arbitrary scripts in the context of users visiting the compromised pages, potentially leading to data theft or session hijacking.
How can I mitigate the risks associated with CVE-2007-6704?
Mitigation steps for CVE-2007-6704 include upgrading to unaffected versions of F5 FirePass 4100 and implementing proper input validation and sanitization.
Is CVE-2007-6704 considered a high-severity vulnerability?
Yes, CVE-2007-6704 is classified as a high-severity vulnerability due to its potential impact on user security and data integrity.