imPC@ndo IT

Tracker / CVE-2005-3057

CVE-2005-3057

High 10.0

The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.

Affected products and versions

fortinet fortigate
fortinet fortios · … → 2.8_mr10
fortinet fortios · … → 3_beta

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References