CVE-2023-23779

6.8MEDIUM

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and b

게시됨: 2/16/2023업데이트됨: 11/21/2024

설명

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthorized code or commands via crafted parameters of HTTP requests.

AI 분석AI 기반

영향받는 제품

fortinetfortiweb
fortinetfortiweb
6.4.0
fortinetfortiweb
6.4.1
fortinetfortiweb
6.4.2
fortinetfortiweb
7.0.0
fortinetfortiweb
7.0.1

참조