Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg5p-7m49-jgfj

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.

EPSS

Процентиль: 44%
0.00218
Низкий

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 4.2
nvd
около 4 лет назад

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to execute arbitrary commands on the underlying system shell via specially crafted command arguments.

EPSS

Процентиль: 44%
0.00218
Низкий

Дефекты

CWE-78