Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-13379 — CVE-2018-13379 fortiOS vulnerability POC | Kitploit
Tools/GitHubGitHub/zierax/cve-2018-13379
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubzierax/cve-2018-13379

CVE-2018-13379

CVE-2018-13379 fortiOS vulnerability POC

View Repository
2116 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-13379 - FortiGate SSL-VPN Path Traversal PoC

Description

Proof-of-Concept script for CVE-2018-13379, a critical path traversal vulnerability in Fortinet FortiGate SSL VPN web portal. This vulnerability allows unauthenticated attackers to download system files via specially crafted HTTP resource requests, potentially exposing session files containing sensitive information.

Vulnerability Details

  • CVE ID: CVE-2018-13379
  • CVSS Score: 9.8 (Critical)
  • Affected Versions: FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7, 5.4.6 to 5.4.12
  • Vulnerable Endpoint: /remote/fgt_lang
  • Impact: Unauthenticated file download leading to potential credential disclosure
root@kitploit:~

## Target Format
Targets can be specified in the following formats:
- IP only: `192.168.1.1`
- IP with port: `192.168.1.1:10443`
- Domain: `vpn.example.com`
- Domain with port: `vpn.example.com:8443`

References

  • CVE-2018-13379 Official Entry
  • Fortinet Security Advisory
  • MITRE ATT&CK Technique
Download Tool