Overview
Fortinet FortiADC 3.2, and possibly earlier versions, contains a cross-site scripting vulnerability. (CWE-79)
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Fortinet FortiADC 3.2, and possibly earlier versions, contains a cross-site scripting vulnerability. The "locale" parameter in the "/FortiADC/gui_partA/?locale=en" page is vulnerable to a reflected cross-site scripting attack. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary script in the context of the end-user's browser session. |
Solution
We are currently unaware of a practical solution to this problem. |
Restrict access |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Fortinet, Inc. | Affected | 07 Feb 2014 | 11 Apr 2014 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Temporal | 3.7 | E:POC/RL:W/RC:C |
Environmental | 2.8 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/79.html
- http://www.fortinet.com/products/fortiadc/index.html
- http://seclists.org/fulldisclosure/2014/Apr/53
Credit
Thanks to William Costa for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2014-0331
- Date Public: 11 4월 2014
- Date First Published: 11 4월 2014
- Date Last Updated: 11 4월 2014
- Document Revision: 17
'취약점 정보1' 카테고리의 다른 글
Amtelco miSecureMessages app lacks authentication (0) | 2014.04.13 |
---|---|
ZyXEL Wireless N300 NetUSB Router NBG-419N devices contain multiple vulnerabilities (0) | 2014.04.13 |
Interested in a Heartbleed Challenge? (0) | 2014.04.13 |
Jetpack 2.9.3: Critical Security Update (0) | 2014.04.13 |
VMware Security Advisories (0) | 2014.04.12 |