Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-42756 — Proof-of-concept for a stack-based buffer overflow in FortiWeb, demonstrating unauthenticated remote code execution via crafted HTTP requests when MitB protection is enabled. | Kitploit
Tools/GitHubGitHub/3ndorph1n/cve-2021-42756
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHub3ndorph1n/cve-2021-42756

CVE-2021-42756

Proof-of-concept for a stack-based buffer overflow in FortiWeb, demonstrating unauthenticated remote code execution via crafted HTTP requests when MitB protection is enabled.

View Repository
1343 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-42756

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code execution via specifically crafted HTTP requests.

Summary

When MitB protection is enabled, there is no limit to the length of the protected fields. This can lead to a stack overflow.

PoC

Environment: FortiWeb 6.3.4

References

  • PSIRT Advisories | FortiGuard
Download Tool