PoC Index

CVE-2005-3058

HIGH 7.5EPSS 3.1%

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.09% chance of exploitation in the next 30 days, 87th percentile
Published
2006-02-14
Updated
2024-08-07

ExploitDB entries (1)

References

Related