Release date:
Updated on:
Affected Systems:
Fortinet FortiWeb 5.0.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65303
CVE (CAN) ID: CVE-2013-7181
FortiGate security products can detect and eliminate network threats.
Fortinet FortiWeb 5.0.3 and other versions do not properly filter the "filter" parameter of/user/ldap_user/add. There is a security vulnerability in implementation, this vulnerability allows remote attackers to execute arbitrary HTML and script code in the browser session of the affected site.
<* Source: William Costa
Link: http://secunia.com/advisories/56732
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Fortinet
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.fortinetfirewall.com/index.php
Http://www.fortiguard.com/advisory/FG-IR-14-002/