Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) srctrack, (2) usemfstmpsize, or (3) usemfsvarsize parameter to systemadvancedmisc.php; the (4) port, (5) snaplen, or (6) count parameter to diagpacketcapture.php; the (7) pppoeresethour, (8) pppoeresetminute, (9) wpagrouprekey, or (10) wpagmkrekey parameter to interfaces.php; the (11) pppoeresethour or (12) pppoeresetminute parameter to interfacespppsedit.php; the (13) member[] parameter to interfacesqinqedit.php; the (14) port or (15) retry parameter to loadbalancerpooledit.php; the (16) pkgrepourl parameter to pkgmgrsettings.php; the (17) zone parameter to servicescaptiveportal.php; the port parameter to (18) servicesdnsmasq.php or (19) servicesunbound.php; the (20) cachemaxttl or (21) cacheminttl parameter to servicesunboundadvanced.php; the (22) sshport parameter to systemadvancedadmin.php; the (23) id, (24) tunable, (25) descr, or (26) value parameter to systemadvancedsysctl.php; the (27) firmwareurl, (28) repositoryurl, or (29) branch parameter to systemfirmwaresettings.php; the (30) pfsyncpeerip, (31) synchronizetoip, (32) username, or (33) passwordfld parameter to systemhasync.php; the (34) maxmss parameter to vpnipsecsettings.php; the (35) ntpserver1, (36) ntpserver2, (37) winsserver1, or (38) winsserver2 parameter to vpnopenvpncsc.php; or unspecified parameters to (39) loadbalancerrelayaction.php, (40) loadbalancerrelayactionedit.php, (41) loadbalancerrelayprotocol.php, or (42) loadbalancerrelayprotocoledit.php.
An XSS vulnerability resides in the hostname field of the diagping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfacesgifedit.php and interfacesgreedit.php components.