peter bassill · operator
$ cve CVE-2007-5979 JSON

CVE-2007-5979 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.6% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2007-11-15
Last modified2026-06-16

Affected (1)

VendorProduct
f5firepass 4100

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD