Sploitus

Exploit for Improper Neutralization of Null Byte or NUL Character in Wftpserver Wing Ftp Server

githubexploit · 2025-07-16

Exploit Code

README29 lines
## https://sploitus.com/exploit?id=D9F3E9AF-D9F8-584D-8020-7BAADE478BB0
# CVE-2025-47812

 ## How does this detection method work?

This Nuclei template detects Wing FTP Server instances vulnerable to CVE-2025-47812 by identifying versions older than 7.4.4 exposed in the web client’s HTML response.

![Untitled](https://github.com/user-attachments/assets/806ff24a-d097-4aba-8e11-51e4ec99ddad)


 ## How do I run this script?

1. Download Nuclei from [here](https://github.com/projectdiscovery/nuclei)
2. Copy the template to your local system
3. Run the following command: `nuclei -u https://yourHost.com -t template.yaml` 

## References

  - https://nvd.nist.gov/vuln/detail/CVE-2025-47812
  - https://www.wftpserver.com/
  - https://securityaffairs.com/179861/hacking/wing-ftp-server-flaw-actively-exploited-shortly-after-technical-details-were-made-public.html

## Disclaimer

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

## Contact

Feel free to reach out to me via [Signal](https://signal.me/#eu/0Qd68U1ivXNdWCF4hf70UYFo7tB0w-GQqFpYcyV6-yr4exn2SclB6bFeP7wTAxQw) if you have any questions or concerns.