Sploitus

Exploit for CVE-2025-49132

kitploit · 2026-08-25

Exploit Code

MARKDOWN46 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-PXXDROBITS-CVE-2025-49132
# 🛡️ Pterodactyl Panel Vulnerability Checker & Exploit Tool

![Typing SVG](https://readme-typing-svg.demolab.com?font=Fira+Code&weight=700&size=24&pause=1500&color=00FF94%C2%A2er=true&width=600&lines=Pentest+Tool+for+Pterodactyl;OSINT+%7C+Exploit+%7C+Automation)

![GitHub stars](https://img.shields.io/github/stars/nfoltc/CVE-2025-49132?style=for-the-badge) ![GitHub issues](https://img.shields.io/github/issues/nfoltc/CVE-2025-49132?style=for-the-badge) ![GitHub forks](https://img.shields.io/github/forks/nfoltc/CVE-2025-49132?style=for-the-badge) ![GitHub license](https://img.shields.io/github/license/nfoltc/CVE-2025-49132?style=for-the-badge)

* * *

## ✨ О программе

**Python-скрипт** , который автоматизирует обнаружение и эксплуатацию уязвимостей в неправильно настроенных панелях **Pterodactyl**.

  * 🔍 Обнаруживает раскрытие конфиденциальных конфигураций (файл `locale.json`).
  * 🔑 Извлекает учётные данные базы данных MySQL.
  * 👑 Автоматически создаёт пользователя-администратора с полным доступом.
  * ☁️ Обнаруживает и пропускает панели, защищённые Cloudflare.



* * *

## ⚙️ Технологии и зависимости

![](https://img.shields.io/badge/Python-3776AB?style=for-the-badge&logo=python&logoColor=white) ![](https://img.shields.io/badge/Requests-5282B8?style=for-the-badge&logo=python-requests&logoColor=white) ![](https://img.shields.io/badge/Colorama-FE7E02?style=for-the-badge&logo=python&logoColor=white) ![](https://img.shields.io/badge/PyMySQL-4479A1?style=for-the-badge&logo=mysql&logoColor=white) ![](https://img.shields.io/badge/Bcrypt-002D72?style=for-the-badge&logo=python&logoColor=white)

* * *

## 🚀 Как использовать

  1. Создайте файл `list.txt` с URL-адресами целевых панелей (по одному на строку).

  2. Запустите:




root@kitploit:~
    
    
    python3 main.py list.txt
    

# Авторы

https://github.com/Zen-kun04/CVE-2025-49132