Sploitus

CVE-2005-3058

2 known exploits for CVE-2005-3058

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

Affected products
Fortigate
Fortinet Fortios
≤ 2.8_mr10, 3_beta
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
3.1% (86th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2006-02-14
CVE-2005-3058 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2005-3058

Proof-of-concept code and exploit modules indexed by Sploitus