Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-5979. PoCs published by Jan Fry.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in F5 FirePass 4100 SSL VPN devices. The vulnerability arises from improper sanitization of user-supplied input in the 'backurl' parameter of the 'download_plugin.php3' script.
Description
Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in F5 FirePass 4100 SSL VPN devices. The vulnerability arises from improper sanitization of user-supplied input in the 'backurl' parameter of the 'download_plugin.php3' script.