[CVE-2024-23113] FortiOS, FortiPAM, FortiProxy and FortiWeb (POC)
by Aanya - Thursday October 31, 2024 at 04:47 AM
#11
(11-03-2024, 01:48 PM)Aanya Wrote: Well its hard  Cry Cry  even after bypassing forti source , we dint have a memory location to write to  , after finding that , send a shell code , rewrite it with return address .  or there is some other way that i am not aware of  , we certainly need help from someone who has  bigger brains .

The person who writes the RCE for this they'll have my full respect .  Heart Heart

seems you're so close to get RCE, I hope you do that.
Is there any chance to share that if you got working payload?
Reply
#12
(11-03-2024, 05:36 PM)jump Wrote:
(11-03-2024, 01:48 PM)Aanya Wrote: Well its hard  Cry Cry  even after bypassing forti source , we dint have a memory location to write to  , after finding that , send a shell code , rewrite it with return address .  or there is some other way that i am not aware of  , we certainly need help from someone who has  bigger brains .

The person who writes the RCE for this they'll have my full respect .  Heart Heart

seems you're so close to get RCE, I hope you do that.
Is there any chance to share that if you got working payload?

Any updates here?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 66 2,459 30 minutes ago
Last Post: Mewayem
  new wordpress website takeover vuln (video + poc ) zinzeur 313 27,305 03-28-2026, 02:43 AM
Last Post: toshi99
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,216 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,098 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 80 02-07-2026, 03:32 PM
Last Post: cysc



 Users browsing this thread: