Fortinet

Fortios

236 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Published 29.01.2018 16:29:00
  • Last modified 21.11.2024 03:12:19

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

  • EPSS 4.05%
  • Published 29.11.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the ...

  • EPSS 0.74%
  • Published 13.11.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the...

  • EPSS 1.46%
  • Published 27.10.2017 13:29:00
  • Last modified 20.04.2025 01:37:25

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

  • EPSS 0.35%
  • Published 27.10.2017 13:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.

  • EPSS 11.48%
  • Published 12.09.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

Exploit
  • EPSS 8.78%
  • Published 12.09.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

Exploit
  • EPSS 8.69%
  • Published 12.09.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

  • EPSS 0.31%
  • Published 12.09.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

  • EPSS 0.31%
  • Published 12.09.2017 02:29:00
  • Last modified 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.