FortiWeb 4kC,3kC,1kC & VA Cross Site Vulnerabilities
5 Feb. 2013
Summary
The Vulnerability Laboratory Research Team discovered multiple cross site scripting vulnerabilities in Fortinets FortiWeb 4000C, 3000C/3000CFsx, 1000C, 400C & Virtual Appliance.
Credit:
The information has been provided by Benjamin Kunz Mejri.
A non persistent cross site scripting vulnerability is detected in Fortinets FortiWeb 4000C, 3000C/3000CFsx, 1000C, 400C & Virtual Appliance.The vulnerability allows remote attackers to hijack website customer, moderator or admin sessions with low or medium required user inter action and without local privileged application user account. The vulnerability is located in the Regular Expression - Validation (pcre_expression/validate) module with the bound vulnerable redir and mkey parameters. Successful exploitation results in client side account steal, client side phishing & client-side appliance module context request manipulation.
Proof of Concept:
The client side cross site scripting vulnerability can be exploited by remote attackers without application user account and with medium required user interaction. For demonstration or reproduce ...