Total vulnerabilities in the database
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow an authenticated and remote attackerĀ to inject arbitrary headers.
Software | From | Fixed in |
---|---|---|
fortinet / fortiweb | 6.4.0 | 6.4.0.x |
fortinet / fortiweb | 6.4.1 | 6.4.1.x |
fortinet / fortiweb | 6.4.2 | 6.4.2.x |
fortinet / fortiweb | 7.0.0 | 7.0.0.x |
fortinet / fortiweb | 7.0.1 | 7.0.1.x |
fortinet / fortiweb | 7.0.2 | 7.0.2.x |
fortinet / fortiweb | 6.3.6 | 6.3.21.x |