Fortinet.FortiWeb.admin.Path.Traversal
Description
This indicates an attack attempt to exploit a Path Traversal Vulnerability in Fortinet FortiWeb.
The vulnerability is due to insufficient sanitizing of user-supplied inputs. A remote attacker can exploit this to read or write arbitrary files in a crafted request. Successful exploitation of this vulnerability could lead to arbitrary code execution.
Affected Products
Fortinet FortiWeb 7.0.x prior to 7.0.12
Fortinet FortiWeb 7.2.x prior to 7.2.12
Fortinet FortiWeb 7.4.x prior to 7.4.10
Fortinet FortiWeb 7.6.x prior to 7.6.5
Fortinet FortiWeb 8.0.x prior to 8.0.2
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://fortiguard.fortinet.com/psirt/FG-IR-25-910
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |