Fortinet FortiWeb是美国飞塔(Fortinet)公司的一款Web应用层防火墙,它能够阻断如跨站点脚本、SQL注入、Cookie中毒、schema中毒等攻击的威胁,保证Web应用程序的安全性并保护敏感的数据库内容。 Fortinet FortiWeb 6.15 和 6.15 和 6.0.6.3 和 6.0 Web 3、6.2.4 和 6.2 存在操作系统命令注入漏洞,该漏洞源于允许执行中的操作系统(操作系统中的命令插入)未经授权的代码或通过个人设计的 HTTP 请求发出的命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-21817 | 9.3 CRITICAL | Nvidia Omniverse Launcher 代码问题漏洞 |
| CVE-2021-41018 | 8.8 HIGH | Fortinet FortiWeb 操作系统命令注入漏洞 |
| CVE-2022-0366 | 8.8 HIGH | Capsule8 Console SQL注入漏洞 |
| CVE-2022-22509 | 8.8 HIGH | PHOENIX CONTACT: FL SWITCH 2xxx series incorrect privilege assignment |
| CVE-2021-42753 | 8.1 HIGH | Fortinet FortiWeb 路径遍历漏洞 |
| CVE-2021-41016 | 7.8 HIGH | Fortinet FortiExtender 操作系统命令注入漏洞 |
| CVE-2022-22510 | 7.5 HIGH | CODESYS: Null Pointer Dereference in CODESYS PROFINET stack |
| CVE-2022-21724 | 7.0 HIGH | Unchecked Class Instantiation when providing Plugin Classes |
| CVE-2020-26208 | 5.3 MEDIUM | Heap-buffer-overflow in jhead |
| CVE-2021-36177 | 4.2 MEDIUM | Fortinet FortiAuthenticator 安全漏洞 |
| CVE-2021-39066 | IBM Financial Transaction Manager 授权问题漏洞 | |
| CVE-2022-24301 | Minetest 安全漏洞 | |
| CVE-2022-24300 | Minetest 安全漏洞 | |
| CVE-2021-24043 | Facebook WhatsApp 缓冲区错误漏洞 | |
| CVE-2021-39044 | IBM Financial Transaction Manager 跨站请求伪造漏洞 | |
| CVE-2022-24069 | Insyde InsydeH2O 权限许可和访问控制问题漏洞 | |
| CVE-2021-39070 | IBM Security Verify Access 安全漏洞 | |
| CVE-2021-42633 | PrinterLogic Web Stack SQL注入漏洞 | |
| CVE-2021-42637 | PrinterLogic Web Stack 代码问题漏洞 | |
| CVE-2021-42639 | PrinterLogic Web Stack 跨站脚本漏洞 |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet