vendor:
PANOS
by:
Thomas Pollet
5.5
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: PANOS
Affected Version From: <= 5.0.8
Affected Version To: 5.0.8
Patch Exists: YES
Related CWE:
CPE: a:paloaltonetworks:pan-os:5.0.8
Platforms Tested:
2013
Palo Alto Networks PANOS XSS
Multiple bugs exist in Palo Alto Networks PANOS <= 5.0.8 that allow for cross-site scripting attacks. The firewall web interface does not properly sanitize certificate fields, allowing for HTML injection. Additionally, various file upload forms used by the firewall lack proper CSRF protection.
Mitigation:
Upgrade to PANOS 5.0.9 or later. Ensure proper sanitization of certificate fields and implement CSRF protection for file upload forms.