Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2025-47812 PoC — Wing FTP Server 7.4.3及 安全漏洞

Source
Associated Vulnerability
Title:Wing FTP Server 7.4.3及 安全漏洞 (CVE-2025-47812)
Description:In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.
Description
Wing FTP Server RCE via Lua Injection
Readme
# CVE-2025-47812 – Wing FTP Server RCE via Lua Injection

**Author:** [0xgh057r3c0n](https://github.com/0xgh057r3c0n)  
---

## 🧠 Description

This exploit leverages a Lua injection vulnerability in **Wing FTP Server**'s login handler (`loginok.html`) to execute arbitrary operating system commands or gain a reverse shell. It abuses unsanitized Lua code execution through the `username` parameter.

---

## 📦 Requirements

- Python 3.6 or higher
- `pip3`

### Python Packages

Install the required packages with:

```bash
pip3 install -r requirements.txt
````

Or manually:

```bash
pip3 install requests colorama
```

---

## 🛠️ Installation

```bash
git clone https://github.com/0xgh057r3c0n/CVE-2025-47812.git
cd CVE-2025-47812
python3 CVE-2025-47812.py
```

---

## 🚀 Usage

Run the script:

```bash
python3 CVE-2025-47812.py
```

### Options:

* **Option 1:** Execute a system command (e.g., `whoami`, `id`)
* **Option 2:** Launch a reverse shell (multiple payload options included)

---

## 💡 Example

```text
Target URL (e.g., http://localhost:5466): http://192.168.1.100:5466
Username (e.g., anonymous): anonymous
Your choice (1 or 2): 1
Command to execute (default: whoami): whoami
```

---

## ⚠️ Legal Disclaimer

This tool is provided for **educational and authorized security testing purposes only**.
You are responsible for your actions. Use only on systems you own or are authorized to test.

---

## 📄 License

This project is licensed under the MIT License. See the [LICENSE](LICENSE) file for details.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →