Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-3058

EPSS 2.65% · P86
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-3058

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Fortinet FortiGate URL检查过滤绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Fortinet FortiGate是美国飞塔(Fortinet)公司开发的一套网络安全平台。该平台提供防火墙、防病毒和入侵防御(IPS)、应用控制、反垃圾邮件、无线控制器和广域网加速等功能。 运行FortiOS 2.8MR10和v3beta的Fortinet FortiGate 2.8版本在处理HTTP请求的URL过滤时存在漏洞。远程攻击者可利用此漏洞绕过检查过滤。如果HTTP请求的每行都以CR而不是CRLF结束的话,或如果HTTP/1.0请求中没有主机字段的话,Fortinet就会无法解析,导致恶意U
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-3058

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-3058

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-02-14 · 17 CVEs total

CVE-2006-0006Microsoft Windows Media Player畸形位图文件处理堆溢出漏洞
CVE-2006-0382Apple Mac OS X 拒绝服务漏洞
CVE-2006-0451Fedora Directory Server多个内存泄露漏洞
CVE-2006-0452Fedora Directory Server多个远程拒绝服务漏洞
CVE-2006-0453Fedora Directory Server多个远程拒绝服务漏洞
CVE-2005-3342Noweb不安全临时文件创建漏洞
CVE-2006-0004Microsoft PowerPoint 2000远程信息泄露漏洞
CVE-2005-3057Fortinet FortiGate反病毒引擎绕过检测漏洞
CVE-2006-0005Microsoft Windows Media Player插件缓冲区溢出漏洞
CVE-2006-0008Microsoft Windows韩语输入法编辑器权限提升漏洞
CVE-2006-0013Microsoft Windows Web Client缓冲区溢出漏洞
CVE-2006-0021Microsoft Windows畸形IGMPv3报文远程拒绝服务漏洞
CVE-2006-0553PostgreSQL远程SET ROLE命令权限提升漏洞
CVE-2006-0678PostgreSQL "SET SESSION AUTHORIZATION"命令拒绝服务漏洞
CVE-2005-3240Microsoft Internet Explorer拖放文件安全漏洞变体
CVE-2006-0677CrossFire拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2005-3058

No comments yet


Leave a comment