AnĀ improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user via crafted HTTP requests.
2023-02-16T19:15:12.467
2024-11-21T07:02:32.090
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiweb | < 6.3.20 | Yes |
Application | fortinet | fortiweb | 6.4.0 | Yes |
Application | fortinet | fortiweb | 6.4.1 | Yes |
Application | fortinet | fortiweb | 6.4.2 | Yes |
Application | fortinet | fortiweb | 7.0.0 | Yes |
Application | fortinet | fortiweb | 7.0.1 | Yes |