Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
watchTowr-vs-SmarterMail-CVE-2025-52691 | Kitploit
ツール/GitHubGitHub/watchtowrlabs/watchtowr-vs-smartermail-cve-2025-52691
脆弱性分析エクスプロイトウェブアプリケーション悪用情報収集ペネトレーションテストレッドチーミング
GitHubwatchtowrlabs/watchtowr-vs-smartermail-cve-2025-52691

watchTowr-vs-SmarterMail-CVE-2025-52691

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
1937ヶ月前未レビュー

CVE-2025-52691 SmarterMail Pre-Auth RCE

SmarterMail Pre-Auth RCE 1day 検出アーティファクト生成ツール

検出の動作

Detection Artifact Generator は、.aspx ファイルを C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data ディレクトリ(ビルド 94xx)または C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data ディレクトリ(ビルド 16)に書き込もうとします。これはリモートコード実行には至りません。単に悪用可能性を証明するだけです。

スクリプトは以下でテストされました:

  • Windows Server ベースのインストール
  • ビルド 94xx および古いビルド 16

一部の古いビルド(SmarterMail 15 など)はテストされていません。

脆弱なインスタンスに対するサンプル実行:

root@kitploit:~
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-SmarterMail-CVE-2025-52691.py
        (*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE

          - Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

[+] VULNERABLE - file epoyn5_0.aspx got uploaded

パッチ適用済みインスタンスに対するサンプル実行:

root@kitploit:~
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-SmarterMail-CVE-2025-52691.py
        (*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE

          - Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

[-] NOT VULNERABLE - patch applied (INVALID_GUID error message appeared)

説明

このスクリプトは、SmarterMail が CVE-2025-52691 の事前認証 RCE に対して脆弱であるかどうかを検出しようとします。

影響を受けるバージョン

< SmarterMail 9413

<= SmarterMail 16.3.6989.16341

watchTowr Labs をフォロー

最新のセキュリティ研究については、watchTowr Labs チームをフォローしてください。

  • https://labs.watchtowr.com/

  • https://x.com/watchtowrcyber

ツールをダウンロード