Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Fortiauthenticator
(Fortinet)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 17 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2018-05-31 | CVE-2018-9186 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. | Fortiauthenticator | 6.1 | ||
2015-02-03 | CVE-2015-1459 | Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/. | Fortiauthenticator | N/A | ||
2015-02-03 | CVE-2015-1458 | Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the "shell" command. | Fortiauthenticator | N/A | ||
2015-02-03 | CVE-2015-1457 | Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command. | Fortiauthenticator | N/A | ||
2015-02-03 | CVE-2015-1456 | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/. | Fortiauthenticator | N/A | ||
2015-02-03 | CVE-2015-1455 | Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors. | Fortiauthenticator | N/A | ||
2014-04-30 | CVE-2013-6990 | FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. | Fortiauthenticator | N/A |