Lucene search

K
cveMitreCVE-2008-1503
HistoryMar 25, 2008 - 7:44 p.m.

CVE-2008-1503

2008-03-2519:44:00
CWE-79
mitre
web.nvd.nist.gov
32
cve-2008-1503
cross-site scripting
xss
f5 big-ip
web management interface
remote attackers
csrf
snmp
audit log xss
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

61.3%

Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a node object, or the (2) sysContact or (3) sysLocation SNMP configuration field, aka “Audit Log XSS.” NOTE: these issues might be resultant from cross-site request forgery (CSRF) vulnerabilities.

Affected configurations

Nvd
Node
f5tmosMatch9.4.3
VendorProductVersionCPE
f5tmos9.4.3cpe:2.3:o:f5:tmos:9.4.3:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

61.3%

Related for CVE-2008-1503