Show filters
874 Total Results
Displaying 251-260 of 874
Sort by:
Attacker Value
Unknown

CVE-2023-37935

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.
Attacker Value
Unknown

CVE-2023-36637

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
Attacker Value
Unknown

CVE-2023-36556

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.
Attacker Value
Unknown

CVE-2023-36555

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.
Attacker Value
Unknown

CVE-2023-36550

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Attacker Value
Unknown

CVE-2023-36549

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Attacker Value
Unknown

CVE-2023-36548

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Attacker Value
Unknown

CVE-2023-36547

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Attacker Value
Unknown

CVE-2023-34993

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.
Attacker Value
Unknown

CVE-2023-34992

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0 through 6.7.5 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 allows attacker to execute unauthorized code or commands via crafted API requests.