Skip to main content

Tags CVE-2013-5649

Juniper VPN SSL: client-side cross-site scripting

Description

The Juniper VPN SSL system was found to be vulnerable to a client-side cross site scripting vulnerability.

Impact

Exploitation of this vulnerability may allow hijack of VPN SSL sessions. This usually involves a social engineering attack in order to convince a logged in victim to click on an attacker-supplied URL. Therefore such an attack would typically be the result of a targeted attack rather than an opportunistic one.

Read more about Juniper VPN SSL: client-side cross-site scripting