Fortinet Fortiweb Multiple Security Vulnerabilities
BID:65660
Info
Fortinet Fortiweb Multiple Security Vulnerabilities
| Bugtraq ID: | 65660 |
| Class: | Unknown |
| CVE: |
CVE-2014-1955 CVE-2014-1956 CVE-2014-1957 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2014 12:00AM |
| Updated: | Feb 13 2014 12:00AM |
| Credit: | Robert van Hamburg of Intermax Security |
| Vulnerable: |
Fortinet FortiWeb 5.0.2 Fortinet FortiWeb 4.4.7 |
| Not Vulnerable: |
Fortinet FortiWeb 5.0.3 |
Discussion
Fortinet Fortiweb Multiple Security Vulnerabilities
Fortinet Fortiweb is prone to multiple security vulnerabilities, including;
1. A cross-site scripting vulnerability
2. A security-bypass vulnerability
3. An HTTP Header Injection Vulnerability
An attacker can exploit these issues to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials, bypass security restrictions to obtain sensitive information, or insert arbitrary headers into an HTTP response, which may help them launch other attacks.
Fortinet Fortiweb 5.0.2 and prior are vulnerable.
Fortinet Fortiweb is prone to multiple security vulnerabilities, including;
1. A cross-site scripting vulnerability
2. A security-bypass vulnerability
3. An HTTP Header Injection Vulnerability
An attacker can exploit these issues to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials, bypass security restrictions to obtain sensitive information, or insert arbitrary headers into an HTTP response, which may help them launch other attacks.
Fortinet Fortiweb 5.0.2 and prior are vulnerable.
Exploit / POC
Fortinet Fortiweb Multiple Security Vulnerabilities
Attackers can use a browser or common networking tools to exploit these issues. To exploit cross-site scripting vulnerability attackers must trick an unsuspecting victim into following a malicious URI.
Attackers can use a browser or common networking tools to exploit these issues. To exploit cross-site scripting vulnerability attackers must trick an unsuspecting victim into following a malicious URI.
Solution / Fix
Fortinet Fortiweb Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Fortinet Fortiweb Multiple Security Vulnerabilities
References:
References:
- Fortinet Homepage (Fortinet)
- FortiWeb Multiple Vulnerabilities (Fortinet)