Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2021-36191
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
0
Attacker Value
Unknown
CVE-2021-42757
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
0
Attacker Value
Unknown
CVE-2021-36180
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.
0
Attacker Value
Unknown
CVE-2021-36187
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests
0
Attacker Value
Unknown
CVE-2021-36186
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
0