
Outil de détection et d'exploitation de la CVE-2025-25257 dans Fortinet FortiWeb.
Crédits
Based on watchTowr Labs, 0xbigshaq, and pwner.gg analyses.
Avertissements
For educational purposes only. Use on authorized systems. Modifies database/filesystem.
Outil Python amélioré pour détecter et exploiter CVE-2025-25257 (SQLi pré-auth vers RCE dans Fortinet FortiWeb).
python exploit.py --host target.com --https --exploit
--host: Target host.
--https: Use HTTPS.
--exploit: Perform exploit if vulnerable.
Installation
pip install -r requirements.txt