peter bassill · operator
$ cve CVE-2005-3058 JSON

CVE-2005-3058 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.09% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2005-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
fortinetfortigate
fortinetfortios

Public exploits

SourceTitleDate
exploit-dbFortinet Fortigate 2.x/3.0 - URL Filtering Bypass2006-02-13

References

→ the Explorer  ·  watch your stack  ·  NVD