Vulnerabilities > CVE-2007-0187 - Input Validation vulnerability in F5 Firepass
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 14 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html
- http://osvdb.org/39167
- http://secunia.com/advisories/23626
- http://secunia.com/advisories/23640
- http://www.mnin.org/advisories/2007_firepass.pdf
- http://www.securityfocus.com/bid/21957
- https://tech.f5.com/home/solutions/sol6916.html
- https://tech.f5.com/home/solutions/sol6924.html