CVE-2015-1880
NUCLEIFortinet Fortios - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Nuclei Templates (1)
Fortinet FortiOS <=5.2.3 - Cross-Site Scripting
MEDIUMby pikpikcu
Shodan:
http.html:"/remote/login" "xxxxxxxx" || http.favicon.hash:945408572 || cpe:"cpe:2.3:o:fortinet:fortios" || port:10443 http.favicon.hash:945408572
FOFA:
body="/remote/login" "xxxxxxxx" || icon_hash=945408572
References (6)
Scores
EPSS
0.5936
EPSS Percentile
98.3%
Details
CWE
CWE-79
Status
published
Products (3)
fortinet/fortios
5.2.0
fortinet/fortios
5.2.1
fortinet/fortios
5.2.2
Published
May 12, 2015
Tracked Since
Feb 18, 2026