Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
BID:32017
Info
Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 32017 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Nov 04 2008 04:05PM |
| Credit: | Kestutis Gudinavicius |
| Vulnerable: |
Fortinet FortiGate-1000 3.00 Fortinet FortiGate 800F Fortinet FortiGate 800 Fortinet FortiGate 60M Fortinet FortiGate 60 Fortinet FortiGate 50AM Fortinet FortiGate 50A Fortinet FortiGate 500A Fortinet FortiGate 5000 Fortinet FortiGate 500 Fortinet FortiGate 400A Fortinet FortiGate 4000 Fortinet FortiGate 400 Fortinet FortiGate 3600 Fortinet FortiGate 300A Fortinet FortiGate 3000 Fortinet FortiGate 300 Fortinet FortiGate 3.00 Fortinet FortiGate 200A Fortinet FortiGate 200 Fortinet FortiGate 100A Fortinet FortiGate 1000AFA2 Fortinet FortiGate 1000A Fortinet FortiGate 1000 Fortinet FortiGate 100 |
| Not Vulnerable: | |
Discussion
Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
Fortinet FortiGate is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data included in unspecified pages.
Few details regarding this vulnerability are available. We will update this BID when more information emerges.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the vulnerable application. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
We don't know which FortiGate devices are affected. We will update this BID when more information emerges.
Fortinet FortiGate is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data included in unspecified pages.
Few details regarding this vulnerability are available. We will update this BID when more information emerges.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the vulnerable application. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
We don't know which FortiGate devices are affected. We will update this BID when more information emerges.
Exploit / POC
Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
To exploit this issue, an attacker entices an unsuspecting user into following a malicious URI.
To exploit this issue, an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Fortinet FortiGate Unspecified Cross Site Scripting Vulnerability
References:
References:
- Fortinet Homepage (Fortinet)