CVE-2017-7733
- EPSS 1.28%
- Veröffentlicht 27.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary javascript code via webUI "Login Disclaimer" redir parameter.
CVE-2017-3131
- EPSS 7.68%
- Veröffentlicht 12.09.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
CVE-2017-3132
- EPSS 8.11%
- Veröffentlicht 12.09.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.
CVE-2017-3133
- EPSS 10.68%
- Veröffentlicht 12.09.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
CVE-2017-7734
- EPSS 0.79%
- Veröffentlicht 12.09.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.
CVE-2017-7735
- EPSS 0.79%
- Veröffentlicht 12.09.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.
CVE-2017-3130
- EPSS 1.45%
- Veröffentlicht 10.08.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.
CVE-2017-3127
- EPSS 0.96%
- Veröffentlicht 01.06.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
CVE-2017-3128
- EPSS 0.71%
- Veröffentlicht 23.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.
CVE-2016-7541
- EPSS 0.95%
- Veröffentlicht 30.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in prox...