imPC@ndo IT

Tracker / CVE-2014-8618

CVE-2014-8618

Medium 4.3

Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products and versions

fortinet fortiadc-1500d
fortinet fortiadc-2000d
fortinet fortiadc-200d
fortinet fortiadc-4000d
fortinet fortiadc-700d
fortinet fortiadc_firmware · … → 4.1.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References