Fortinet

Fortios

236 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 29.01.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:12:19

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

  • EPSS 4.05%
  • Veröffentlicht 29.11.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the ...

  • EPSS 0.74%
  • Veröffentlicht 13.11.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the...

  • EPSS 1.46%
  • Veröffentlicht 27.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

  • EPSS 0.35%
  • Veröffentlicht 27.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.

  • EPSS 11.48%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

Exploit
  • EPSS 8.78%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

Exploit
  • EPSS 8.69%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

  • EPSS 0.31%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

  • EPSS 0.31%
  • Veröffentlicht 12.09.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.