Sploitus

Exploit for Path Traversal in Fortinet Fortiproxy

githubexploit · 2020-12-14

Exploit Code

README10 lines
## https://sploitus.com/exploit?id=01DA9660-6518-515F-8B1D-245590DED6BF
## Usage & Disclaimer

This script is a batch detection tool for the Fortinet FortiOS path traversal vulnerability (CVE-2018-13379). Usage: `Python CVE-2018-13379.py url.txt`.

The vulnerability addresses are listed in vul.txt.

##### Affected Versions:

Fortinet FortiOS versions 5.6.3 to 5.6.7, and 6.0.0 to 6.0.4 are affected by this vulnerability. The vulnerability arises from the system’s failure to properly filter special characters in resource or file paths, allowing attackers to access locations outside of the restricted directories. This tool is intended only for security personnel’s safety testing. Any direct or indirect consequences or losses caused by unauthorized detection are the responsibility of the user.