SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.org/files/111276/F5-FirePass-SSL-VPN-6.x-7.x-SQL-Injection.html - | |
References | () http://seclists.org/fulldisclosure/2012/Mar/324 - | |
References | () http://secunia.com/advisories/48455 - | |
References | () http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13463.html - Vendor Advisory | |
References | () http://www.securitytracker.com/id?1026834 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74198 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74450 - | |
References | () https://www.sec-consult.com/files/20120328-0_F5_FirePass_SSL_VPN_unauthenticated_remote_root_v1.0.txt - Exploit |
Information
Published : 2012-04-05 14:55
Updated : 2024-11-21 01:37
NVD link : CVE-2012-1777
Mitre link : CVE-2012-1777
CVE.ORG link : CVE-2012-1777
JSON object : View
Products Affected
f5
- firepass
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')