Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiweb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-39951
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 up to and including 7.0.2, FortiWeb version 6.3.6 up to and including 6.3.20, FortiWeb 6.4 all versions allows malicious user to execute unaut...
Fortinet Fortiweb
801
VMScore
CVE-2021-41018
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows malicious user to execute unauthorized code or commands via crafted HTTP requests.
Fortinet Fortiweb
356
VMScore
CVE-2021-41026
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 up to and including 6.3.15 may allow an authenticated malicious user to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Fortinet Fortiweb
312
VMScore
CVE-2014-1458
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and previous versions allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors.
Fortinet Fortiweb
578
VMScore
CVE-2020-29018
A format string vulnerability in FortiWeb 6.3.0 up to and including 6.3.5 may allow an authenticated, remote malicious user to read the content of memory and retrieve sensitive data via the redir parameter.
Fortinet Fortiweb
605
VMScore
CVE-2016-4066
Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb prior to 5.5.3 allows remote malicious users to hijack the authentication of administrators for requests that change the password via unspecified vectors.
Fortinet Fortiweb
383
VMScore
CVE-2013-7181
Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remote malicious users to inject arbitrary web script or HTML via the filter parameter.
Fortinet Fortiweb 5.0.3
890
VMScore
CVE-2017-14189
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
Fortinet Fortiweb Manager 5.8.0
668
VMScore
CVE-2020-29015
A blind SQL injection in the user interface of FortiWeb 6.3.0 up to and including 6.3.7 and version prior to 6.2.4 may allow an unauthenticated, remote malicious user to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing ...
Fortinet Fortiweb
445
VMScore
CVE-2020-29019
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 up to and including 6.3.7 and version prior to 6.2.4 may allow a remote, unauthenticated malicious user to crash the httpd daemon thread by sending a request with a crafted cookie header.
Fortinet Fortiweb
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
NEXT »