Multiple Fortinet FortiGate Appliances Multiple Cross Site Scripting Vulnerabilities
BID:55591
Info
Multiple Fortinet FortiGate Appliances Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 55591 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2012 12:00AM |
| Updated: | Sep 18 2012 12:00AM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: |
Fortinet FortiGate 5000 Fortinet FortiGate 3950 Fortinet FortiGate 3810A |
| Not Vulnerable: | |
Discussion
Multiple Fortinet FortiGate Appliances Multiple Cross Site Scripting Vulnerabilities
Multiple Fortinet FortiGate Appliances are prone to multiple cross-site scripting vulnerabilities because they fail to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Multiple Fortinet FortiGate Appliances are prone to multiple cross-site scripting vulnerabilities because they fail to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Solution / Fix
Multiple Fortinet FortiGate Appliances Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly, the issues have been fixed, however, Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Reportedly, the issues have been fixed, however, Symantec has not confirmed it. Please contact the vendor for more information.
References
Multiple Fortinet FortiGate Appliances Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Fortigate Homepage (Fortinet)