Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiweb vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2020-29018
A format string vulnerability in FortiWeb 6.3.0 up to and including 6.3.5 may allow an authenticated, remote malicious user to read the content of memory and retrieve sensitive data via the redir parameter.
Fortinet Fortiweb
5
CVSSv2
CVE-2020-29019
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 up to and including 6.3.7 and version prior to 6.2.4 may allow a remote, unauthenticated malicious user to crash the httpd daemon thread by sending a request with a crafted cookie header.
Fortinet Fortiweb
3.5
CVSSv2
CVE-2020-6646
An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated malicious user to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message.
Fortinet Fortiweb
Fortinet Fortiweb 6.3.0
4
CVSSv2
CVE-2019-16157
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and previous versions may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
Fortinet Fortiweb
4.3
CVSSv2
CVE-2019-16156
An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated malicious user to perform a Cross Site Scripting attack (XSS).
Fortinet Fortiweb
Fortinet Fortiweb 6.2.0
3.5
CVSSv2
CVE-2015-3612
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and previous versions and 5.0.10 and previous versions via an unspecified parameter in the FortiWeb auto update service page.
Fortinet Fortimanager
4.3
CVSSv2
CVE-2019-5590
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an malicious user to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.
Fortinet Fortiweb
4.3
CVSSv2
CVE-2017-14191
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows malicious user to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
Fortinet Fortiweb
4.3
CVSSv2
CVE-2012-6346
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb prior to 4.4.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.
Fortinet Fortiweb
10
CVSSv2
CVE-2017-14189
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
Fortinet Fortiweb Manager 5.8.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
NEXT »