
FortiWeb における CVE-2025-64446 認証バイパスを、パストラバーサルを悪用して検出し、管理者権限なしで脆弱性を確認します。
Bishop Fox による FortiWeb 認証バイパススキャナー
この脆弱性の詳細については、Bishop Fox のブログ を参照してください。
git clone https://github.com/BishopFox/fortiweb-auth-bypass-check
cd fortiweb-auth-bypass-check
python3 -m pip install requests
python3 scan.py https://[TARGET]
# Vulnerable target
$ python3 scan.py https://example1.com
[*] Testing https://example1.com
[!] Target is VULNERABLE - update immediately!
# Unaffected target
$ python3 scan.py https://example2.com
[*] Testing https://example2.com
[+] Target is not affected
# Invalid target
$ python3 scan.py https://example3.com
[*] Testing https://example3.com
[-] Target does not appear to be FortiWeb
このコードは MIT ライセンス の下で配布されています。