Page 131 of 797 results (0.010 seconds)

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie. Una vulnerabilidad de control de acceso inadecuado en Fortinet FortiWeb versión 5.6.0 hasta 6.1.0 en "Signed Security Mode", permite al atacante omitir la protección de la cookie de usuario firmada eliminando la propia cookie de sesión de protección de FortiWeb. • http://www.securityfocus.com/bid/103430 https://fortiguard.com/advisory/FG-IR-17-279 •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf, (2) mapolicymgmt/targetsMonitorView.jsf, (3) vascan/globalsummary.jsf, (4) vaerrorlog/vaErrorLog.jsf, (5) database/listTargetGroups.jsf, (6) sysconfig/listSystemInfo.jsf, (7) vascan/list.jsf, (8) network/router.jsf, (9) mapolicymgmt/editPolicyProfile.jsf, or (10) mapolicymgmt/maPolicyMasterList.jsf. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en la manipulación de excepciones de formato de número en Java en FortiGate FortiDB, en versiones anteriores a la 4.4.2, permiten que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro conversationContext en (1) admin/auditTrail.jsf, (2) mapolicymgmt/targetsMonitorView.jsf, (3) vascan/globalsummary.jsf, (4) vaerrorlog/vaErrorLog.jsf, (5) database/listTargetGroups.jsf, (6) sysconfig/listSystemInfo.jsf, (7) vascan/list.jsf, (8) network/router.jsf, (9) mapolicymgmt/editPolicyProfile.jsf o (10) mapolicymgmt/maPolicyMasterList.jsf. • https://fortiguard.com/psirt/FG-IR-012-007 https://www.vulnerability-lab.com/get_content.php?id=558 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate. Múltiples vulnerabilidades de tipo Cross-Site Scripting (XSS) en FortiWeb, en versiones anteriores a la 4.4.4, permiten que atacantes remotos inyecten scripts web o HTML mediante los parámetros (1) redir o (2) mkey en waf/pcre_expression/validate. • https://fortiguard.com/psirt/FG-IR-012-008 https://www.vulnerability-lab.com/get_content.php?id=702 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en dispositivos Fortinet FortiGate UTM WAF con FortiOS, en versiones 4.3.x anteriores a la 4.3.6, permiten que atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores relacionados con los módulos (1) Endpoint Monitor, (2) Dialup List o (3) LogReport Display o el parámetro fields_sorted_opt en (4) user/auth/list o (5) endpointcompliance/app_detect/predefined_sig_list. • http://packetstormsecurity.org/files/109168/VL-144.txt http://www.securityfocus.com/bid/51708 https://exchange.xforce.ibmcloud.com/vulnerabilities/72761 https://fortiguard.com/psirt/FG-IR-012-001 https://securitytracker.com/id/1026594 https://www.vulnerability-lab.com/get_content.php?id=144 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. Una vulnerabilidad de Cross-Site Scripting (XSS) en Fortinet FortiOS 5.6.0 a 5.6.2; 5.4.0 a 5.4.7 y 5.2 y anteriores permite que un atacante inyecte scripts web o HTML arbitrarios mediante una cabecera "Host" maliciosamente manipulada en las peticiones HTTP de usuario. • http://www.securityfocus.com/bid/102779 http://www.securitytracker.com/id/1040284 https://fortiguard.com/advisory/FG-IR-17-262 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •