Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-6704. PoCs published by Richard Brain, Adrian Pastor.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in F5 Networks FirePass 4100 SSL VPN devices. The PoC uses an iframe with a malicious URL to inject arbitrary JavaScript code, potentially stealing authentication credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.
Exploits (2)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in F5 Networks FirePass 4100 SSL VPN devices. The PoC uses an iframe with a malicious URL to inject arbitrary JavaScript code, potentially stealing authentication credentials.
This exploit demonstrates a cross-site scripting (XSS) vulnerability in F5 FirePass 4100 SSL VPN devices by injecting arbitrary HTML/JS via unsanitized input in the 'my.activation.php3' endpoint.