|
Fortinet Fortigate Firewall contains a flaw that potentially allows a remote attacker to gain the administrator credentials. The issue is due to the session cookie containing both the username and MD5 hash of the password. In conjunction with the XSS attacks, a remote attacker could trick the administrator into disclosing the contents of the cookie.
|