Show filters
173 Total Results
Displaying 131-140 of 173
Sort by:
Attacker Value
Unknown
CVE-2018-1353
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.
0
Attacker Value
Unknown
CVE-2017-17541
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
0
Attacker Value
Unknown
NetIQ iManager XSS vulnerabilities
Disclosure Date: July 10, 2018 (last updated November 08, 2023)
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
0
Attacker Value
Unknown
CVE-2018-1351
Disclosure Date: June 28, 2018 (last updated November 26, 2024)
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
0
Attacker Value
Unknown
CVE-2018-1355
Disclosure Date: June 27, 2018 (last updated November 26, 2024)
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
0
Attacker Value
Unknown
CVE-2018-1354
Disclosure Date: June 27, 2018 (last updated November 26, 2024)
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
0
Attacker Value
Unknown
iManager elevation of privilege
Disclosure Date: March 21, 2018 (last updated November 08, 2023)
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
0
Attacker Value
Unknown
NetIQ iManager Communication Downgrade Attack
Disclosure Date: March 21, 2018 (last updated November 08, 2023)
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
0
Attacker Value
Unknown
NetIQ iManager, versions prior to 3.1, reflected XSS issue
Disclosure Date: March 21, 2018 (last updated November 08, 2023)
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
0
Attacker Value
Unknown
private SSL key embedded in JAR file in iManager
Disclosure Date: March 02, 2018 (last updated November 08, 2023)
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
0