Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
kentico-xperience13-AuthBypass-wt-2025-0006 — Kentico Xperience 13 CMS Staging Service 向けの認証バイパス検出スクリプト。単一のPOSTリクエストを使用して脆弱性を検証します。 | Kitploit
ツール/GitHubGitHub/watchtowrlabs/kentico-xperience13-authbypass-wt-2025-0006
認証と認可脆弱性分析ウェブアプリケーション悪用ウェブセキュリティペネトレーションテスト
GitHubwatchtowrlabs/kentico-xperience13-authbypass-wt-2025-0006

kentico-xperience13-AuthBypass-wt-2025-0006

Kentico Xperience 13 CMS Staging Service 向けの認証バイパス検出スクリプト。単一のPOSTリクエストを使用して脆弱性を検証します。

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
531年前未レビュー

WT-2025-0006 (CVE は未割り当て)

Kentico Xperience 13 CMS - Staging Service 認証バイパスチェック

実行例

root@kitploit:~
python3 watchTowr-vs-kentico-xperience13-AuthBypass-wt-2025-0006.py -H http://labcms
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-kentico-xperience13-AuthBypass-wt-2025-0006.py
        (*) WT-2025-0006: Kentico Xperience 13 CMS - Staging Service Authentication Bypass Check

          - Piotr Bazydlo (@chudyPB) of watchTowr

        CVEs: TBD

[+] Verifying Authentication Bypass in Staging API
[+] VULNERABLE: Authentication Bypassed!

概要

このスクリプトは、Kentico Xperience 13 CMS の Staging Service に対する認証バイパスを試みます。単一の POST リクエストを送信し、API のレスポンスを解析します。

影響を受けるバージョン

  • Kentico Xperience 13(Hotfix 173 より前)
  • 構成: Staging Service がユーザー名/パスワード認証で有効になっている必要があります

他の Kentico Xperience バージョン(Kentico Xperience 12 など)はテストされていません。

注意

Staging Service がユーザー名/パスワード認証で有効になっているターゲットに対してのみ動作します

watchTowr Labs をフォロー

最新のセキュリティ研究については、watchTowr Labs チームをフォローしてください

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
ツールをダウンロード