cve201813379_fortigate_ssl_vpn_arbitrary_file_reading
Description
FortiOS system file leak through SSL VPN via specially crafted HTTP resource requests. This exploit read /dev/cmdb/sslvpn_websession file, this file contains login and passwords in (clear/text). This vulnerability affect ( FortiOS 5.6.3 to 5.6.7 and FortiOS 6.0.0 to 6.0.4 ). License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
re.regex($selection.target.url, `.*/remote/fgt_lang\?lang=/\.\./\.\./\.\./\.\.//////////dev/cmdb/sslvpn_websession.*`)
condition:
$selection