Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2021-41025
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper synchronization and one of authentication bypass by capture-replay, may allow a remote unauthenticated attacker to circumvent the authentication process and authenticate as a legitimate cluster peer.
0
Attacker Value
Unknown
CVE-2021-41017
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2021-36195
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.
0
Attacker Value
Unknown
CVE-2021-41013
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
0
Attacker Value
Unknown
CVE-2021-43063
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.
0
Attacker Value
Unknown
CVE-2021-36190
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2021-43064
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
0
Attacker Value
Unknown
CVE-2021-41027
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.
0
Attacker Value
Unknown
CVE-2021-41015
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler
0
Attacker Value
Unknown
CVE-2021-41014
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
0