Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2023-34988

Disclosure Date: October 10, 2023 (last updated October 12, 2023)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
Attacker Value
Unknown

CVE-2023-34987

Disclosure Date: October 10, 2023 (last updated October 12, 2023)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
Attacker Value
Unknown

CVE-2023-34986

Disclosure Date: October 10, 2023 (last updated October 12, 2023)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
Attacker Value
Unknown

CVE-2023-34985

Disclosure Date: October 10, 2023 (last updated October 12, 2023)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
Attacker Value
Unknown

CVE-2021-43070

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Attacker Value
Unknown

CVE-2021-43077

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the AP monitor handlers.
Attacker Value
Unknown

CVE-2021-43075

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the alarm dashboard and controller config handlers.
Attacker Value
Unknown

CVE-2021-42760

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.
Attacker Value
Unknown

CVE-2021-42752

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests
Attacker Value
Unknown

CVE-2021-41029

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests