Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
fortiweb-auth-bypass-check | Kitploit
Tools/GitHubGitHub/bishopfox/fortiweb-auth-bypass-check
Vulnerability ScannersWeb Application ExploitationWeb SecurityPenetration Testing
GitHubbishopfox/fortiweb-auth-bypass-check

fortiweb-auth-bypass-check

View Repository
58 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

FortiWeb Auth Bypass Check

FortiWeb auth bypass scanner by Bishop Fox

  • Tests a target for authentication bypass CVE-2025-64446
  • Only exploits a path traversal, does not exploit the actual auth bypass
  • Does not perform any administrative actions on the target

For more information about this vulnerability, refer to the Bishop Fox blog.

Setup

root@kitploit:~
git clone https://github.com/BishopFox/fortiweb-auth-bypass-check
cd fortiweb-auth-bypass-check
python3 -m pip install requests

Usage

root@kitploit:~
python3 scan.py https://[TARGET]

Examples

root@kitploit:~
# Vulnerable target
$ python3 scan.py https://example1.com
[*] Testing https://example1.com
[!] Target is VULNERABLE - update immediately!

# Unaffected target
$ python3 scan.py https://example2.com
[*] Testing https://example2.com
[+] Target is not affected

# Invalid target
$ python3 scan.py https://example3.com
[*] Testing https://example3.com
[-] Target does not appear to be FortiWeb

License

This code is distributed under an MIT license.

Download Tool