Fortinet FortiWeb是美国飞塔(Fortinet)公司的一款Web应用层防火墙,它能够阻断如跨站点脚本、SQL注入、Cookie中毒、schema中毒等攻击的威胁,保证Web应用程序的安全性并保护敏感的数据库内容。 Fortinet FortiWeb 7.6.3及之前版本、7.4.7及之前版本、7.2.10及之前版本和7.0.10之前版本存在SQL注入漏洞,该漏洞源于对SQL命令中特殊元素中和不当,可能导致SQL注入攻击。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257 | POC详情 |
| 2 | FortiWeb CVE-2025-25257 exploit | https://github.com/0xbigshaq/CVE-2025-25257 | POC详情 |
| 3 | Tool for detecting and exploiting CVE-2025-25257 in Fortinet FortiWeb. | https://github.com/adilburaksen/CVE-2025-25257-Exploit-Tool | POC详情 |
| 4 | None | https://github.com/imbas007/CVE-2025-25257 | POC详情 |
| 5 | CVE-2025-25257 | https://github.com/B1ack4sh/Blackash-CVE-2025-25257 | POC详情 |
| 6 | PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated. | https://github.com/0xgh057r3c0n/CVE-2025-25257 | POC详情 |
| 7 | Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection. | https://github.com/aitorfirm/CVE-2025-25257 | POC详情 |
| 8 | CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s | https://github.com/mrmtwoj/CVE-2025-25257 | POC详情 |
| 9 | Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE | https://github.com/TheStingR/CVE-2025-25257 | POC详情 |
| 10 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25257.yaml | POC详情 |
| 11 | A working (at least for me :] ) exploit for CVE-2025-25257 | https://github.com/segfault-it/CVE-2025-25257 | POC详情 |
| 12 | 🛠️ Exploit CVE-2025-25257 in FortiWeb with a working full exploit and a proof of concept for file read/write. | https://github.com/kityzed2003/CVE-2025-25257 | POC详情 |
| 13 | PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated. | https://github.com/zr1p3r/CVE-2025-25257 | POC详情 |
| 14 | None | https://github.com/silentexploitexe/CVE-2025-25257 | POC详情 |
| 15 | CVE-2025-25257 PoC for educational use and/or authorised pentesting. | https://github.com/mr-r3b00t/CVE-2025-25257 | POC详情 |
| 16 | CVE-2025-25257 | https://github.com/Ashwesker/Blackash-CVE-2025-25257 | POC详情 |
| 17 | None | https://github.com/lytianahkone-boop/cve-2025-25257 | POC详情 |
| 18 | CVE-2025-25257 | https://github.com/Ashwesker/Ashwesker-CVE-2025-25257 | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论