Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiweb vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2021-36193
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb prior to 6.4.2 may allow an authenticated malicious user to achieve arbitrary code execution via specially crafted commands.
Fortinet Fortiweb
8.8
CVSSv3
CVE-2021-41018
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows malicious user to execute unauthorized code or commands via crafted HTTP requests.
Fortinet Fortiweb
6.5
CVSSv3
CVE-2021-41026
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 up to and including 6.3.15 may allow an authenticated malicious user to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Fortinet Fortiweb
8.8
CVSSv3
CVE-2023-34984
A protection mechanism failure in Fortinet FortiWeb 7.2.0 up to and including 7.2.1, 7.0.0 up to and including 7.0.6, 6.4.0 up to and including 6.4.3, 6.3.6 up to and including 6.3.23 allows malicious user to execute unauthorized code or commands via specially crafted HTTP reques...
Fortinet Fortiweb
8.8
CVSSv3
CVE-2020-29018
A format string vulnerability in FortiWeb 6.3.0 up to and including 6.3.5 may allow an authenticated, remote malicious user to read the content of memory and retrieve sensitive data via the redir parameter.
Fortinet Fortiweb
NA
CVE-2014-1955
Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb prior to 5.0.3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Fortinet Fortiweb
NA
CVE-2014-1956
CRLF injection vulnerability in FortiGuard FortiWeb prior to 5.0.3 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Fortinet Fortiweb
6.5
CVSSv3
CVE-2020-15942
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated malicious user to read the password used by the FortiWeb scanner to access the device def...
Fortinet Fortiweb
6.5
CVSSv3
CVE-2019-16157
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and previous versions may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
Fortinet Fortiweb
6.1
CVSSv3
CVE-2021-22122
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 up to and including 6.3.7 and version prior to 6.2.4 may allow an unauthenticated, remote malicious user to perform a reflected cross site scripting attack (XSS) by injecting malicious ...
Fortinet Fortiweb
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »