Record summary

CVE-2005-3058 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFortinet Fortigate 2.x/3.0 - URL Filtering BypassExploitDB exploitby Mathieu DessusNot analyzed1 file
ExploitDB

PoC details

References

8