ID
VAR-201608-0437
TITLE
Fortinet FortiVoice HTML Injection vulnerability
Trust: 0.6
DESCRIPTION
Fortinet FortiVoice is a complete business telephone system developed by Fortinet. Fortinet FortiVoice 5.0.4 and earlier versions have an HTML injection vulnerability that is caused by the program's insufficient filtering of user-submitted input. When a user browses an affected website, their browser executes any HTML or script code provided by the attacker. This could lead to an attacker stealing cookie-based authentication. Fortinet FortiVoice is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input. Fortinet FortiVoice 5.0.4 and prior are vulnerable
Trust: 0.81
AFFECTED PRODUCTS
vendor: | fortinet | model: | fortivoice | scope: | eq | version: | 5.0.4 | Trust: 0.3 |
vendor: | fortinet | model: | fortivoice | scope: | ne | version: | 5.0.5 | Trust: 0.3 |
THREAT TYPE
remote
Trust: 0.6
TYPE
input validation
Trust: 0.6
EXTERNAL IDS
db: | BID | id: | 92455 | Trust: 0.9 |
db: | CNNVD | id: | CNNVD-201608-377 | Trust: 0.6 |
REFERENCES
url: | http://www.securityfocus.com/bid/92455 | Trust: 0.6 |
url: | http://www.fortinet.com/ | Trust: 0.3 |
url: | http://fortiguard.com/advisory/fortivoice-5-0-filter-bypass-persistent-web-vulnerabilities | Trust: 0.3 |
CREDITS
Vulnerability Lab
Trust: 0.9
SOURCES
db: | BID | id: | 92455 |
db: | CNNVD | id: | CNNVD-201608-377 |
LAST UPDATE DATE
2022-05-17T01:57:42.820000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 92455 | date: | 2016-08-15T00:00:00 |
db: | CNNVD | id: | CNNVD-201608-377 | date: | 2016-08-19T00:00:00 |
SOURCES RELEASE DATE
db: | BID | id: | 92455 | date: | 2016-08-15T00:00:00 |
db: | CNNVD | id: | CNNVD-201608-377 | date: | 2016-08-19T00:00:00 |