Show filters
107 Total Results
Displaying 81-90 of 107
Sort by:
Attacker Value
Unknown
CVE-2018-13375
Disclosure Date: May 28, 2019 (last updated November 27, 2024)
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature enabled).
0
Attacker Value
Unknown
CVE-2018-1360
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
0
Attacker Value
Unknown
CVE-2018-1353
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.
0
Attacker Value
Unknown
CVE-2017-17541
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
0
Attacker Value
Unknown
CVE-2018-1351
Disclosure Date: June 28, 2018 (last updated November 26, 2024)
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
0
Attacker Value
Unknown
CVE-2018-1355
Disclosure Date: June 27, 2018 (last updated November 26, 2024)
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.
0
Attacker Value
Unknown
CVE-2018-1354
Disclosure Date: June 27, 2018 (last updated November 26, 2024)
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
0
Attacker Value
Unknown
CVE-2015-3617
Disclosure Date: August 22, 2017 (last updated November 26, 2024)
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
0
Attacker Value
Unknown
CVE-2015-3616
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
0
Attacker Value
Unknown
CVE-2015-3615
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
0