Show filters
874 Total Results
Displaying 261-270 of 874
Sort by:
Attacker Value
Unknown
CVE-2023-34989
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
0
Attacker Value
Unknown
CVE-2023-34988
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
0
Attacker Value
Unknown
CVE-2023-34987
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
0
Attacker Value
Unknown
CVE-2023-34986
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
0
Attacker Value
Unknown
CVE-2023-34985
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.
0
Attacker Value
Unknown
CVE-2023-33301
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.
0
Attacker Value
Unknown
CVE-2023-25607
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiADC 7.1.0, 7.0.0 through 7.0.3, 6.2 all versions, 6.1 all versions, 6.0 all versions management interface may allow an authenticated attacker with at least READ permissions on system settings to execute arbitrary commands on the underlying shell due to an unsafe usage of the wordexp function.
0
Attacker Value
Unknown
CVE-2023-25604
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs.
0
Attacker Value
Unknown
CVE-2022-22298
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.
0
Attacker Value
Unknown
CVE-2023-40717
Disclosure Date: September 13, 2023 (last updated February 25, 2025)
A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the device to access the database via shell commands.
0