FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1032185 | vdb entry |
http://www.fortiguard.com/advisory/FG-IR-15-009/ | vendor advisory |