# N/A
## 概述
Fortinet FortiOS 和 FortiProxy 的 SSL VPN web 门户中存在路径遍历漏洞。攻击者可以通过精心构造的 HTTP 资源请求下载系统文件,而无需经过身份验证。
## 影响版本
- FortiOS: 6.0.0 到 6.0.4, 5.6.3 到 5.6.7, 5.4.6 到 5.4.12
- FortiProxy: 2.0.0, 1.2.0 到 1.2.8, 1.1.0 到 1.1.6, 1.0.0 到 1.0.7
## 细节
该漏洞是由于路径名限制不当导致的路径遍历。攻击者利用此漏洞可以从受影响的系统中下载系统文件,而无需进行身份验证。攻击者通过发送特殊的 HTTP 资源请求来实现这一目标。
## 影响
攻击者可以下载系统文件,这可能导致敏感信息泄露、系统配置的暴露以及潜在的安全风险。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | CVE-2018-13379 | https://github.com/milo2012/CVE-2018-13379 | POC详情 |
| 2 | Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network. | https://github.com/jpiechowka/at-doom-fortigate | POC详情 |
| 3 | CVE-2018-13379 Exploit | https://github.com/0xHunter/FortiOS-Credentials-Disclosure | POC详情 |
| 4 | CVE-2018-13379 Script for Nmap NSE. | https://github.com/Blazz3/cve2018-13379-nmap-script | POC详情 |
| 5 | None | https://github.com/yukar1z0e/CVE-2018-13379 | POC详情 |
| 6 | None | https://github.com/pwn3z/CVE-2018-13379-FortinetVPN | POC详情 |
| 7 | FortiVuln | https://github.com/k4nfr3/CVE-2018-13379-Fortinet | POC详情 |
| 8 | This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (CVE-2018-13379). | https://github.com/Zeop-CyberSec/fortios_vpnssl_traversal_leak | POC详情 |
| 9 | Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本 | https://github.com/B1anda0/CVE-2018-13379 | POC详情 |
| 10 | Hunting CVE-2018-13379 | https://github.com/nivdolgin/CVE-2018-13379 | POC详情 |
| 11 | An exploit for Fortinet CVE-2018-13379 | https://github.com/Farzan-Kh/CVE-2018-13379 | POC详情 |
| 12 | Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests due to improper limitation of a pathname to a restricted directory (path traversal). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13379.yaml | POC详情 |
| 13 | CVE-2018-13379 - Fortinet SSL VPN Vulnerability | https://github.com/kh4sh3i/CVE-2018-13379 | POC详情 |
暂无评论