ESF.pfSense.Squid.Clwarn.PHP.XSS

description-logoDescription

This indicates an attack attempt against a Cross-Site Scripting vulnerability in ESF pfSense.
The vulnerability is due to insufficient validation of a maliciously crafted HTTP request. An attacker can exploit this to execute arbitrary script code within the context of the application.

affected-products-logoAffected Products

PFSense Project PFSense 2.3.1-RELEASE-p1

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code within the context of application.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the website.
https://www.pfsense.org/security/advisories/pfSense-SA-16_06.squid.asc

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)