
FOGProject 인증 우회 CVE-2025-58443 익스플로잇
https://github.com/FOGProject/fogproject에 대한 exploit POC로, 인증 우회를 통해 전체 DB 덤프가 포함된 DB를 덤프할 수 있으며, 여기에는 평문 비밀번호, 사용자 및 관리자 비밀번호 해시가 포함됩니다.
취약한 버전 : 1.5.10.1673
다음은 이 취약점을 악용할 수 있는 스크립트로, 다음 작업을 수행할 수 있습니다 : 전체 MySQL DB 덤프 SSRF 취약점 악용 서버의 파일 목록 나열
DB 덤프에는 해시된 비밀번호와 FTP 등의 평문 비밀번호가 포함되어 있습니다 ...
결과 :
SSRF 악용 :
파일 목록 나열 악용 :
I, the creator, am not responsible for any actions, and or damages, caused by this software.
You bear the full responsibility of your actions and acknowledge that this software was created for educational purposes only.
This software's main purpose is NOT to be used maliciously, or on any system that you do not own, or have the right to use.
By using this software, you automatically agree to the above.