Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xrh-w83g-7mfh

Опубликовано: 07 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.

EPSS

Процентиль: 55%
0.00325
Низкий

8.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
почти 4 года назад

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically crafted HTTP requests.

CVSS3: 7.2
fstec
почти 4 года назад

Уязвимость веб-интерфейса системы балансировки трафика FortiWAN, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 55%
0.00325
Низкий

8.8 High

CVSS3

Дефекты

CWE-78