This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.
The remote host is affected by a cross-site scripting vulnerability.
The remote host is running FortiWeb 5.x prior to 5.1.0. It is,
therefore, affected by a cross-site scripting vulnerability in the web
UI due to a failure to sanitize user-supplied input to the 'filter'
parameter in the '/user/ldap_user/add' script. An attacker could
in the context of the end-user's browser.
See also :
Upgrade to 5.1.0 or later.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true