CVE-2005-3058
Last modified
CVE-2005-3058 is a vulnerability of currently unknown severity. Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.. EPSS estimates a 3.10% chance of exploitation in the next 30 days.
Description
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | <= 2.8_mr10 |
| Fortinet | Fortios | <= 3_beta |
| Fortinet | Fortigate | 2.8 |
References
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3058?
How severe is CVE-2005-3058?
How do I fix CVE-2005-3058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3052SQL injection vulnerability in module/down.inc.php in jporta…
- CVE-2005-3053The sys_set_mempolicy function in mempolicy.c in Linux kerne…
- CVE-2005-3054fopen_wrappers.c in PHP 4.4.0, and possibly other versions, …
- CVE-2005-3055Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause…
- CVE-2005-3056TWiki allows arbitrary shell command execution via the Inclu…9.8
- CVE-2005-3057The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 a…
- CVE-2005-3059Multiple unspecified vulnerabilities in Opera 8.50 on Linux …
- CVE-2005-3060Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows loca…
- CVE-2005-3061Multiple stack-based buffer overflows in PowerArchiver 8.10 …
- CVE-2005-3062PHP remote file inclusion vulnerability in index.php in Alst…
- CVE-2005-3063SQL injection vulnerability in MailGust 1.9 allows remote at…
- CVE-2005-3064MultiTheftAuto 0.5 patch 1 and earlier does not properly ver…
Are you affected by CVE-2005-3058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
