Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortiweb  >> 6.3.21  Security Vulnerabilities
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 through 6.3.21, 6.4.0 through 6.4.2 and 7.0.0 through 7.0.4 may allow a local attacker to access confidential configuration files via a crafted http request.
CVSS Score
7.0
EPSS Score
0.0
Published
2023-02-27
A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.
CVSS Score
4.9
EPSS Score
0.001
Published
2023-02-16
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attackerĀ to inject arbitrary headers.
CVSS Score
5.4
EPSS Score
0.004
Published
2023-01-03


Contact Us

Shodan ® - All rights reserved