Show filters
46 Total Results
Displaying 41-46 of 46
Sort by:
Attacker Value
Unknown

CVE-2015-1458

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command.
0
Attacker Value
Unknown

CVE-2015-1456

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
0
Attacker Value
Unknown

CVE-2015-1455

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1459

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.
0
Attacker Value
Unknown

CVE-2013-6990

Disclosure Date: April 30, 2014 (last updated October 05, 2023)
FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
0
Attacker Value
Unknown

CVE-2012-6140

Disclosure Date: April 24, 2013 (last updated October 05, 2023)
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.
0