Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiGate URL检查过滤绕过漏洞
Vulnerability Description
Fortinet FortiGate是美国飞塔(Fortinet)公司开发的一套网络安全平台。该平台提供防火墙、防病毒和入侵防御(IPS)、应用控制、反垃圾邮件、无线控制器和广域网加速等功能。 运行FortiOS 2.8MR10和v3beta的Fortinet FortiGate 2.8版本在处理HTTP请求的URL过滤时存在漏洞。远程攻击者可利用此漏洞绕过检查过滤。如果HTTP请求的每行都以CR而不是CRLF结束的话,或如果HTTP/1.0请求中没有主机字段的话,Fortinet就会无法解析,导致恶意U
CVSS Information
N/A
Vulnerability Type
N/A