A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated malicious user to access protected hosts via crafted HTTP requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fortinet fortiweb 6.4.0 |
||
fortinet fortiweb |
||
fortinet fortiweb 6.4.1 |
||
fortinet fortiweb 6.1.0 |
||
fortinet fortiweb 6.1.1 |
||
fortinet fortiweb 6.1.2 |