目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-25257 PoC — Fortinet FortiWeb SQL注入漏洞

来源
关联漏洞
标题: Fortinet FortiWeb SQL注入漏洞 (CVE-2025-25257)
Description:Fortinet FortiWeb是美国飞塔(Fortinet)公司的一款Web应用层防火墙,它能够阻断如跨站点脚本、SQL注入、Cookie中毒、schema中毒等攻击的威胁,保证Web应用程序的安全性并保护敏感的数据库内容。 Fortinet FortiWeb 7.6.3及之前版本、7.4.7及之前版本、7.2.10及之前版本和7.0.10之前版本存在SQL注入漏洞,该漏洞源于对SQL命令中特殊元素中和不当,可能导致SQL注入攻击。
介绍
# CVE-2025-25257 - FortiWeb Vulnerability Checker & Exploit

A Python-based tool for checking and exploiting CVE-2025-25257 vulnerability in FortiWeb devices. This vulnerability allows SQL injection and remote code execution through a crafted Authorization header.


## 📋 Description

CVE-2025-25257 is a critical vulnerability in FortiWeb devices that allows:
- SQL injection via the Authorization header
- Remote code execution through webshell upload
- Unauthorized access to vulnerable systems

## 🚀 Features

- **Automated vulnerability detection** for single targets or bulk scanning
- **SQL injection exploitation** to upload webshells
- **Command execution** via uploaded webshell
- **Bulk target processing** from file input
- **Results logging** with timestamps
- **Comprehensive error handling**

## 📦 Requirements

```bash
pip install requests urllib3
```

## 🛠️ Installation

1. Clone the repository:
```bash
git clone https://github.com/yourusername/CVE-2025-25257.git
cd CVE-2025-25257
```

2. Install dependencies:
```bash
pip install -r requirements.txt
```

## 📖 Usage

### Vulnerability Checker (`vuln_check.py`)

Check a single target:
```bash
python3 vuln_check.py -t https://target.com
```

Check multiple targets from a file:
```bash
python3 vuln_check.py -l target.txt
```

### Command Execution (`exp.py`)

Execute commands on a vulnerable target:
```bash
python3 exp.py -t https://target.com -c "id"
```

## 📁 Files

- `vuln_check.py` - Main vulnerability checker and exploit
- `exp.py` - Command execution tool for vulnerable targets
- `target.txt` - Sample list of targets (replace with your own)
- `vuln.txt` - Output file with vulnerable targets (generated after scan)

## 🔍 How It Works

1. **SQL Injection**: Exploits the vulnerable API endpoint `/api/fabric/device/status`
2. **Webshell Upload**: Uses SQL injection to write a webshell to `/cgi-bin/x.cgi`
3. **Command Execution**: Executes commands via the uploaded webshell
4. **Verification**: Tests command execution to confirm successful exploitation

## 📊 Output

The tool generates a `vuln.txt` file containing:
- Timestamp of each scan
- Vulnerable target URLs
- Command execution results
- Scan statistics

Example output:
```
# CVE-2025-25257 Vulnerable Targets - 2025-01-27 10:30:15
# Format: [timestamp] target - command_output

[2025-01-27 10:30:15] https://target.com - uid=0(root) gid=0(root) groups=0(root)
```


---

**credit**:0xbigshaq
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →