Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
BID:27276
Info
Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
| Bugtraq ID: | 27276 |
| Class: | Design Error |
| CVE: |
CVE-2008-7161 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2008 12:00AM |
| Updated: | Apr 16 2015 06:06PM |
| Credit: | H. Daniel Regalado Arias is credited with the discovery of this vulnerability. |
| Vulnerable: |
Fortinet FortiGate-1000 3.00 |
| Not Vulnerable: | |
Discussion
Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
Fortinet Fortigate is prone to a vulnerability that can allow attackers to bypass the device's URL filtering.
An attacker can exploit this issue to view unauthorized websites, bypassing certain security restrictions. This may lead to other attacks.
This issue affects Fortigate-1000 3.00; other versions may also be affected.
NOTE: This issue may be related to the vulnerability described in BID 16599 (Fortinet Fortigate URL Filtering Bypass Vulnerability).
Fortinet Fortigate is prone to a vulnerability that can allow attackers to bypass the device's URL filtering.
An attacker can exploit this issue to view unauthorized websites, bypassing certain security restrictions. This may lead to other attacks.
This issue affects Fortigate-1000 3.00; other versions may also be affected.
NOTE: This issue may be related to the vulnerability described in BID 16599 (Fortinet Fortigate URL Filtering Bypass Vulnerability).
Exploit / POC
Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Fortinet Fortigate CRLF Characters URL Filtering Bypass Vulnerability
References:
References:
- Fortinet Homepage (Fortinet)
- [Dailydave] FortiGuard: URL Filtering Application Bypass Vulnerability (H. Daniel Regalado Arias)