
FOGProject 認証バイパス CVE-2025-58443 エクスプロイト
https://github.com/FOGProject/fogproject 向けのエクスプロイトPOCです。認証バイパスによりDBダンプが可能となり、完全なDBダンプには平文パスワード、ユーザー、管理者パスワードのハッシュが含まれます。
影響を受けるバージョン : 1.5.10.1673
以下はこの脆弱性を悪用するスクリプトで、以下のことが可能です: MySQL DB全体のダンプ SSRF脆弱性の悪用 サーバー上のファイル一覧の取得
DBダンプには、FTPなどのハッシュ化されたパスワードと平文パスワードが含まれます...
結果:
SSRFエクスプロイト:
ファイル一覧エクスプロイト:
I, the creator, am not responsible for any actions, and or damages, caused by this software.
You bear the full responsibility of your actions and acknowledge that this software was created for educational purposes only.
This software's main purpose is NOT to be used maliciously, or on any system that you do not own, or have the right to use.
By using this software, you automatically agree to the above.