Show filters
95 Total Results
Displaying 51-60 of 95
Sort by:
Attacker Value
Unknown
CVE-2021-36195
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.
0
Attacker Value
Unknown
CVE-2021-41013
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
0
Attacker Value
Unknown
CVE-2021-36188
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and error handlers
0
Attacker Value
Unknown
CVE-2021-43063
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.
0
Attacker Value
Unknown
CVE-2021-36190
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.
0
Attacker Value
Unknown
CVE-2021-43064
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
0
Attacker Value
Unknown
CVE-2021-41027
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.
0
Attacker Value
Unknown
CVE-2021-41015
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler
0
Attacker Value
Unknown
CVE-2021-41014
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets
0
Attacker Value
Unknown
CVE-2021-36191
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
0