Vulnerabilities > CVE-2015-1455 - Credentials Management vulnerability in Fortinet Fortiauthenticator 3.0.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | CGI abuses : XSS |
NASL id | FORTIAUTHENTICATOR_CVE_2015_1459.NASL |
description | The remote Fortinet FortiAuthenticator appliance is affected by a cross-site scripting vulnerability due to improper validation of input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 81383 |
published | 2015-02-16 |
reporter | This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/81383 |
title | Fortinet FortiAuthenticator 'operation' Parameter XSS |
code |
|
References
- http://packetstormsecurity.com/files/130156/Fortinet-FortiAuthenticator-XSS-Disclosure-Bypass.html
- http://packetstormsecurity.com/files/130156/Fortinet-FortiAuthenticator-XSS-Disclosure-Bypass.html
- http://www.fortiguard.com/advisory/FG-IR-15-003/
- http://www.fortiguard.com/advisory/FG-IR-15-003/
- http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiAuthenticator_Multiple_Vulnerabilities.pdf
- http://www.security-assessment.com/files/documents/advisory/Fortinet_FortiAuthenticator_Multiple_Vulnerabilities.pdf
- http://www.securityfocus.com/bid/72378
- http://www.securityfocus.com/bid/72378