CVE-2012-0941
https://notcve.org/view.php?id=CVE-2012-0941
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en dispositivos Fortinet FortiGate UTM WAF con FortiOS, en versiones 4.3.x anteriores a la 4.3.6, permiten que atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores relacionados con los módulos (1) Endpoint Monitor, (2) Dialup List o (3) LogReport Display o el parámetro fields_sorted_opt en (4) user/auth/list o (5) endpointcompliance/app_detect/predefined_sig_list. • http://packetstormsecurity.org/files/109168/VL-144.txt http://www.securityfocus.com/bid/51708 https://exchange.xforce.ibmcloud.com/vulnerabilities/72761 https://fortiguard.com/psirt/FG-IR-012-001 https://securitytracker.com/id/1026594 https://www.vulnerability-lab.com/get_content.php?id=144 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-14190
https://notcve.org/view.php?id=CVE-2017-14190
A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. Una vulnerabilidad de Cross-Site Scripting (XSS) en Fortinet FortiOS 5.6.0 a 5.6.2; 5.4.0 a 5.4.7 y 5.2 y anteriores permite que un atacante inyecte scripts web o HTML arbitrarios mediante una cabecera "Host" maliciosamente manipulada en las peticiones HTTP de usuario. • http://www.securityfocus.com/bid/102779 http://www.securitytracker.com/id/1040284 https://fortiguard.com/advisory/FG-IR-17-262 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-7738
https://notcve.org/view.php?id=CVE-2017-7738
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command. Una vulnerabilidad de divulgación de información en Fortinet FortiOS de la versión 5.6.0 a la 5.6.2; 5.4.0 a la 5.4.5 y la versión 5.2 y anteriores permite que un usuario administrador con privilegios super_admin vea la información de sesión del portal web SSL VPN, que podría contener credenciales a través del comando CLI fnsysctl. • http://www.securityfocus.com/bid/102151 https://fortiguard.com/advisory/FG-IR-17-172 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-14186 – FortiGate SSL VPN Portal 5.x Cross Site Scripting
https://notcve.org/view.php?id=CVE-2017-14186
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via the affected parameter. Una vulnerabilidad de tipo Cross-site Scripting (XSS) en Fortinet FortiOS versión 6.0.0 hasta 6.0.4, versión 5.6.0 hasta 5.6.7, versión 5.4 e inferiores, en el portal web SSL VPN permite a un usuario remoto inyectar scripting web o HTML arbitrarias en el contexto del navegador de la víctima por medio del parámetro redir login. Un ataque de redirección de URL también puede ser posible inyectando una URL externa mediante el parámetro afectado. FortiGate SSL VPN Portal versions 5.6.2 and below, 5.4.6 and below, 5.2.12 and below, and 5.0 and below suffer from a cross site scripting vulnerability. • http://www.securityfocus.com/bid/101955 http://www.securitytracker.com/id/1039891 https://fortiguard.com/advisory/FG-IR-17-242 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-7739
https://notcve.org/view.php?id=CVE-2017-7739
A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim. Una vulnerabilidad de Cross-Site Scripting reflejado en las páginas web de respuesta a mensajes de proxies web en Fortinet FortiOS en versiones 5.6.0, 5.4.0 a la 5.4.5 y la 5.2.0 a la 5.2.11 permite que un atacante sin autenticar inyecte scripts web o HTML arbitrarios en el contexto del navegador de la víctima enviando una URL maliciosamente manipulada a la víctima. • http://www.securityfocus.com/bid/101679 http://www.securitytracker.com/id/1039741 https://fortiguard.com/advisory/FG-IR-17-168 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •