Vulnerable Systems:
* F5 FirePass SSL VPN 4xxx Series
F5 FirePass SSL VPN contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the "refreshURL" parameter upon submission to the "my.activation.cns.php3" script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing.