Page 12 of 61 results (0.015 seconds)

CVSS: 6.1EPSS: 0%CPEs: 19EXPL: 0

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim. Una vulnerabilidad de Cross-Site Scripting reflejado en las páginas web de respuesta a mensajes de proxies web en Fortinet FortiOS en versiones 5.6.0, 5.4.0 a la 5.4.5 y la 5.2.0 a la 5.2.11 permite que un atacante sin autenticar inyecte scripts web o HTML arbitrarios en el contexto del navegador de la víctima enviando una URL maliciosamente manipulada a la víctima. • http://www.securityfocus.com/bid/101679 http://www.securitytracker.com/id/1039741 https://fortiguard.com/advisory/FG-IR-17-168 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 7EXPL: 0

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter. Una vulnerabilidad de Cross-Site Scripting (XSS) en Fortinet FortiOS desde la versión 5.4.0 a la 5.4.5 y en la versión 5.6.0 permite que un atacante remoto no autenticado ejecute código JavaScfript arbitrario mediante el parámetro de redirección "Login Disclaimer" en la interfaz gráfica de usuario web. • http://www.securityfocus.com/bid/101563 http://www.securitytracker.com/id/1039677 https://fortiguard.com/psirt/FG-IR-17-113 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 32EXPL: 0

An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets. Una vulnerabilidad de divulgación de información en Fortinet FortiOS 5.6.0, 5.4.4 y versiones inferiores permite que un atacante obtenga la información de la versión de FortiOS mediante la inspección de paquetes FortiOS IKE VendorID. • http://www.securityfocus.com/bid/100211 https://fortiguard.com/advisory/FG-IR-17-073 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.4EPSS: 43%CPEs: 6EXPL: 1

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView. Una vulnerabilidad de tipo Cross-Site Scripting en Fortinet FortiOS desde la versión 5.4.0 hasta la 5.4.4 y la versión 5.6.0 permite que atacantes remotos ejecuten código o comandos sin autorización mediante la entrada de filtro en "Applications" en FortiView. FortiOS versions 5.6.0 and below suffer from multiple cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/42388 http://www.securityfocus.com/bid/100009 http://www.securitytracker.com/id/1039020 https://fortiguard.com/advisory/FG-IR-17-104 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken. Una vulnerabilidad de tipo Cross-Site Scripting en Fortinet FortiOS en su versión 5.6.0 y anteriores permite que atacantes remotos ejecuten código o comandos sin autorización mediante la entrada de acción durante la activación de un FortiToken. FortiOS versions 5.6.0 and below suffer from multiple cross site scripting vulnerabilities. • https://www.exploit-db.com/exploits/42388 http://www.securityfocus.com/bid/100009 http://www.securitytracker.com/id/1039020 https://fortiguard.com/advisory/FG-IR-17-104 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •