Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
参数注入或修改
Vulnerability Title
Fortinet FortiDeceptor 参数注入漏洞
Vulnerability Description
Fortinet FortiDeceptor是美国飞塔(Fortinet)公司的一款网络威胁检测平台。该平台主要通过欺骗技术暴露网络威胁等。 Fortinet FortiDeceptor 6.0.0至6.0.2版本、5.3.0至5.3.3版本、5.2.0至5.2.1版本、5.1所有版本和5.0所有版本存在参数注入漏洞,该漏洞源于命令中参数分隔符中和不当,可能导致具有至少只读管理员权限的经过身份验证的攻击者通过HTTP特制请求读取日志文件。
CVSS Information
N/A
Vulnerability Type
N/A