CVE-2012-1777

F5 FirePass 6.0.0-6.1.0, 7.0.0 - SQL Injection via my.activation.php3 State Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48455
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74450
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74198
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2012/Mar/324
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026834

Scores

EPSS 0.0123
EPSS Percentile 79.4%

Details

CWE
CWE-89
Status published
Products (3)
f5/firepass 6.0
f5/firepass 6.1.0
f5/firepass 7.0.0
Published Apr 05, 2012
Tracked Since Feb 18, 2026