ID

VAR-201302-0182


CVE

CVE-2013-1471


TITLE

Fortinet FortiMail of admin/FEAdmin.html Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2012-005930

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section. Fortinet FortiMail ID Base cipher (IBE) Runs on the appliance Fortinet FortiMail of admin/FEAdmin.html Contains a cross-site scripting vulnerability.By the attacker, through the following items, arbitrary Web Script or HTML May be inserted. FortiMail is currently the most flexible email security system, which can protect and deploy in various email structures and filter spam. Viruses and spyware, to achieve a comprehensive defense system. Multiple cross-site scripting vulnerabilities exist in admin/FEAdmin.html in Fortinet versions prior to FortiMail 4.3.4 on FortiMail Identity-Based Encryption (IBE) based applications. User-assisted attackers could exploit this vulnerability to inject arbitrary web scripts or HTML

Trust: 1.71

sources: NVD: CVE-2013-1471 // JVNDB: JVNDB-2012-005930 // VULHUB: VHN-61473

AFFECTED PRODUCTS

vendor:fortinetmodel:fortimailscope:eqversion:4.0

Trust: 1.6

vendor:fortinetmodel:fortimailscope:eqversion:3.0

Trust: 1.6

vendor:fortinetmodel:fortimailscope:lteversion:4.0

Trust: 1.0

vendor:fortinetmodel:fortimailscope:ltversion:4.3.4

Trust: 0.8

sources: JVNDB: JVNDB-2012-005930 // CNNVD: CNNVD-201302-076 // NVD: CVE-2013-1471

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1471
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-1471
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201302-076
value: MEDIUM

Trust: 0.6

VULHUB: VHN-61473
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-1471
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61473
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61473 // JVNDB: JVNDB-2012-005930 // CNNVD: CNNVD-201302-076 // NVD: CVE-2013-1471

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-61473 // JVNDB: JVNDB-2012-005930 // NVD: CVE-2013-1471

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201302-076

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201302-076

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-005930

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-61473

PATCH

title:Potential Web Vulnerabilities in FortiMailurl:http://www.fortiguard.com/advisory/FG-IR-013-001.html

Trust: 0.8

sources: JVNDB: JVNDB-2012-005930

EXTERNAL IDS

db:NVDid:CVE-2013-1471

Trust: 2.5

db:JVNDBid:JVNDB-2012-005930

Trust: 0.8

db:CNNVDid:CNNVD-201302-076

Trust: 0.7

db:EXPLOIT-DBid:24435

Trust: 0.1

db:SEEBUGid:SSVID-78161

Trust: 0.1

db:VULHUBid:VHN-61473

Trust: 0.1

sources: VULHUB: VHN-61473 // JVNDB: JVNDB-2012-005930 // CNNVD: CNNVD-201302-076 // NVD: CVE-2013-1471

REFERENCES

url:http://www.fortiguard.com/advisory/fg-ir-013-001.html

Trust: 1.7

url:http://www.vulnerability-lab.com/get_content.php?id=701

Trust: 1.7

url:http://www.youtube.com/watch?v=5d7ciam80oy

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1471

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1471

Trust: 0.8

sources: VULHUB: VHN-61473 // JVNDB: JVNDB-2012-005930 // CNNVD: CNNVD-201302-076 // NVD: CVE-2013-1471

SOURCES

db:VULHUBid:VHN-61473
db:JVNDBid:JVNDB-2012-005930
db:CNNVDid:CNNVD-201302-076
db:NVDid:CVE-2013-1471

LAST UPDATE DATE

2024-08-14T14:40:27.239000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61473date:2013-02-08T00:00:00
db:JVNDBid:JVNDB-2012-005930date:2013-02-06T00:00:00
db:CNNVDid:CNNVD-201302-076date:2013-02-05T00:00:00
db:NVDid:CVE-2013-1471date:2013-02-08T05:00:00

SOURCES RELEASE DATE

db:VULHUBid:VHN-61473date:2013-02-04T00:00:00
db:JVNDBid:JVNDB-2012-005930date:2013-02-06T00:00:00
db:CNNVDid:CNNVD-201302-076date:2013-02-05T00:00:00
db:NVDid:CVE-2013-1471date:2013-02-04T19:55:01.833