EIP-2026-101336
PRE-CVEJuniper Networks SA2000 SSL VPN Appliance - 'welcome.cgi' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101336. PoCs published by Richard Brain.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Juniper Networks SA2000 SSL VPN appliance by injecting arbitrary JavaScript code via the 'u' parameter in the logout URL. The vulnerability arises due to insufficient input sanitization in the web interface.
Description
Juniper Networks SA2000 SSL VPN Appliance - 'welcome.cgi' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Juniper Networks SA2000 SSL VPN appliance by injecting arbitrary JavaScript code via the 'u' parameter in the logout URL. The vulnerability arises due to insufficient input sanitization in the web interface.