FirePass SSL VPN could allow a remote attacker to conduct phishing attacks, caused by an error in the my.activation.cns.php script. An attacker could exploit this vulnerability using the refreshURL parameter in a specially-crafted URI to redirect a victim to arbitrary Web sites.