CVE-2023-34989
- EPSS 1.48%
- Published 10.10.2023 17:15:11
- Last modified 21.11.2024 08:07:47
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HT...
CVE-2023-34988
- EPSS 1.48%
- Published 10.10.2023 17:15:11
- Last modified 21.11.2024 08:07:47
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HT...
CVE-2023-34986
- EPSS 1.48%
- Published 10.10.2023 17:15:11
- Last modified 21.11.2024 08:07:46
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HT...
CVE-2023-34985
- EPSS 1.48%
- Published 10.10.2023 17:15:11
- Last modified 21.11.2024 08:07:46
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HT...
CVE-2021-43070
- EPSS 0.39%
- Published 02.03.2022 17:15:07
- Last modified 21.11.2024 06:28:38
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying f...
CVE-2021-43077
- EPSS 0.7%
- Published 01.03.2022 19:15:08
- Last modified 21.11.2024 06:28:39
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized cod...
- EPSS 1.6%
- Published 01.03.2022 19:15:08
- Last modified 21.11.2024 06:28:38
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthoriz...
CVE-2021-42760
- EPSS 0.57%
- Published 08.12.2021 12:15:07
- Last modified 21.11.2024 06:28:07
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.
CVE-2021-42752
- EPSS 0.27%
- Published 08.12.2021 12:15:07
- Last modified 21.11.2024 06:28:05
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript code on victim's host via crafted HTTP requests
CVE-2021-41029
- EPSS 0.55%
- Published 08.12.2021 12:15:07
- Last modified 21.11.2024 06:25:18
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests