6.8
CVSSv2

CVE-2008-7032

Published: 24/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote malicious users to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-ip 9.4.3

Exploits

source: wwwsecurityfocuscom/bid/27720/info F5 BIG-IP is prone to a cross-site request-forgery vulnerability Exploiting this issue may allow a remote attacker to execute arbitrary actions on an affected device F5 BIG-IP 943 is vulnerable; other versions may also be affected wwwexamplecom/tmui/Control/form?handler=%2Ftmui ...