![](/assets/img/cve_300x82_sin_bg.png)
CVE-2022-27489
https://notcve.org/view.php?id=CVE-2022-27489
16 Feb 2023 — A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. • https://fortiguard.com/psirt/FG-IR-22-048 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-15710
https://notcve.org/view.php?id=CVE-2019-15710
31 Oct 2019 — An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands. Una vulnerabilidad de inyección de comandos de Sistema Operativo en FortiExtender versión 4.1.0 a 4.1.1, versión 4.0.0 y anteriores en la consola de administración de la CLI puede permitir que administradores no autorizados ejecuten comandos arbitrarios a nivel del sistema por... • https://fortiguard.com/psirt/FG-IR-19-273 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •