Fortigate Firewall 2.x – listdel Admin Interface Cross-Site Scripting

Fortigate Firewall 2.x – listdel Admin Interface Cross-Site Scripting

漏洞ID 1054248 漏洞类型
发布时间 2003-11-12 更新时间 2003-11-12
图片[1]-Fortigate Firewall 2.x – listdel Admin Interface Cross-Site Scripting-安全小百科CVE编号 N/A
图片[2]-Fortigate Firewall 2.x – listdel Admin Interface Cross-Site Scripting-安全小百科CNNVD-ID N/A
漏洞平台 Hardware CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/23378
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/9033/info
  
Multiple cross-site scripting vulnerabilities have been reported in the FortiGate Firewall web administrative interface.
  
These issues could be exploited by enticing an administrative user to follow a malicious link that includes hostile HTML and script code as values for URI parameters. If such a link is followed, the hostile code may be rendered in the administrator's browser. This could lead to theft of cookie-based authentication credentials, which contain the username and MD5 hash of the password, allowing for full compromise of the firewall.


https://www.example.com/antispam/listdel?file=blacklist&name=b<script>alert('oops')</script>&startline=0

https://www.example.com/antispam/listdel?file=whitelist&name=a<script>alert('oops')</script>&startline=0(naturally)

相关推荐: OpenSource Router CVE-1999-0530 Remote Security Vulnerability

OpenSource Router CVE-1999-0530 Remote Security Vulnerability 漏洞ID 1208776 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 1999…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享