CVE Database
/

CVE-2005-3058

Back to search

CVE-2005-3058

Published: Feb 14, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

VendorProductVersions

n/a

n/a

affected
n/a

References

20060213 URL filter bypass in Fortinet
mailing-list
x_refsource_FULLDISC
20060213 URL filter bypass in Fortinet
mailing-list
x_refsource_BUGTRAQ
fortinet-web-filter-bypass(24626)
vdb-entry
x_refsource_XF
16599
vdb-entry
x_refsource_BID
18844
third-party-advisory
x_refsource_SECUNIA
ADV-2006-0539
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now