CVE-2016-3978: Fortinet FortiOS – Open Redirect/Cross-Site Scripting

CVE-2016-3978: Fortinet FortiOS - Open Redirect/Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2016-3978: Fortinet FortiOS – Open Redirect/Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2016-3978: Fortinet fortios – Open Redirect/Cross-Site Scripting

漏洞描述

FortiOS Web User Interface in 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting attacks via the "redirect" parameter to "login."

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享