
استغلال تجاوز المصادقة في FOGProject CVE-2025-58443
POC استغلال لـ https://github.com/FOGProject/fogproject وهو تجاوز للمصادقة يؤدي إلى تفريغ قاعدة البيانات (DB) والذي يتضمن تفريغاً كاملاً لقاعدة البيانات، ويشمل كلمات مرور بنص واضح والمستخدمين وتجزئة كلمة مرور المسؤول.
الإصدار المعرض للثغرة : 1.5.10.1673
فيما يلي سكربت سيستغل الثغرة ويمكنه القيام بما يلي :
يحتوي تفريغ قاعدة البيانات على كلمات المرور المجزأة وكلمات المرور بنص واضح لخدمات FTP وغيرها ...
النتائج :
استغلال SSRF :
استغلال سرد الملفات :
I, the creator, am not responsible for any actions, and or damages, caused by this software.
You bear the full responsibility of your actions and acknowledge that this software was created for educational purposes only.
This software's main purpose is NOT to be used maliciously, or on any system that you do not own, or have the right to use.
By using this software, you automatically agree to the above.