CVE-2015-5965
https://notcve.org/view.php?id=CVE-2015-5965
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a crafted MAC field. Vulnerabilidad en la funciionalidad SSL-VPN en Fortinet FortiOS en versiones anteriores a 4.3.13, sólo comprueba el primer byte de la TLS MAC en los mensajes finalizados, lo que hace que sea más fácil para atacantes remotos suplantar el contenido cifrado a través de un campo MAC manipulado. • http://www.fortiguard.com/advisory/FG-IR-15-016 http://www.securityfocus.com/bid/76065 http://www.securitytracker.com/id/1033256 https://security.gentoo.org/glsa/201508-01 https://vivaldi.net/en-US/blogs/entry/the-poodle-has-friends • CWE-20: Improper Input Validation •
CVE-2015-7360 – FortiSandbox 3000D 2.02 build0042 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2015-7360
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreatingReport parameter to csearch/report/export/; the (3) id parameter to analysis/detail/download/screenshot; or vectors related to (4) "Fortiview threats by users search filtered by vdom" or (5) "PCAP file download generated by the VM scan feature." Múltiples vulnerabilidades de XSS en la Web User Interface (WebUI) en Fortinet FortiSandbox en versiones anteriores a 2.1 permite a atacantes remotos inyectar secuencias de comandos web o HTLM arbitrarios a través del (1) parámetro serial para alerts/summary/profile/; (2) parámetro urlForCreatingReport para csearch/report/export/; (3) parámetro id para analysis/detail/download/screenshot; o vectores relacionados con (4) "amenazas Fortiview por el filtrado de búsqueda de usuarios por vdom" o (5) "descarga de archivo PCAP generada por la funcionalidad scan VM". FortiSandbox 3000D version 2.02 build004 suffers from a cross site scripting vulnerability. • http://fortiguard.com/advisory/multiple-xss-vulnerabilities-in-fortisandbox-webui http://hyp3rlinx.altervista.org/advisories/AS-FORTISANDBOX-0801.txt http://packetstormsecurity.com/files/132930/FortiSandbox-3000D-2.02-build0042-Cross-Site-Scripting.html http://www.securityfocus.com/archive/1/536124/100/0/threaded • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-1880
https://notcve.org/view.php?id=CVE-2015-1880
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vunerabilidad de XSS en la página de acceso sslvpn en Fortinet FortiOS 5.2.x en versiones anteriores a 5.2.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://www.fortiguard.com/advisory/FG-IR-15-005 http://www.securityfocus.com/bid/74652 http://www.securitytracker.com/id/1032261 http://www.securitytracker.com/id/1032262 http://www.securitytracker.com/id/1032264 http://www.securitytracker.com/id/1032265 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-8618
https://notcve.org/view.php?id=CVE-2014-8618
Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la página de acceso del tema en modelos Fortinet FortiADC D en versiones anteriores a 4.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://www.fortiguard.com/advisory/FG-IR-15-005 http://www.securitytracker.com/id/1032265 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-8616
https://notcve.org/view.php?id=CVE-2014-8616
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) user group or (2) vpn template menus. Múltiples vulnerabilidades de XSS en Fortinet FortiOS 5.2.x anterior a 5.2.3 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios o HTML a través de vectores no especificados en menús (1) de grupos de usuarios o (2) de plantillas vpn. • http://www.fortiguard.com/advisory/FG-IR-15-005 http://www.securitytracker.com/id/1032261 http://www.securitytracker.com/id/1032262 http://www.securitytracker.com/id/1032264 http://www.securitytracker.com/id/1032265 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •