CVE-2025-29306 is a remote code execution vulnerability affecting FoxCMS version 1.2.5. According to the provided information, the issue is reachable via the case display page in the index.html component, where insufficient handling of attacker-controlled input allows a remote attacker to execute arbitrary code. Specific vulnerable functions or parameter names are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository provides a working proof-of-concept (PoC) exploit for CVE-2025-29306, a critical unauthenticated remote code execution (RCE) vulnerability in FoxCMS version 1.2.5 and earlier. The vulnerability arises from unsafe deserialization of user input in the 'id' parameter of the /images/index.html endpoint, allowing attackers to inject PHP code that is executed on the server. The repository contains two exploit scripts: a Python script (CVE-2025-29306.py) and a Bash script (CVE-2025-29306.sh). Both scripts automate the process of crafting a malicious payload, sending it to the vulnerable endpoint, and extracting the output of arbitrary system commands executed on the target. The README.md provides a detailed technical breakdown, risk assessment, and mitigation advice. The exploit requires no authentication and can be executed remotely, making it highly dangerous for unpatched FoxCMS installations. The main fingerprintable endpoint is /images/index.html with the 'id' parameter. The exploit is operational, providing real command execution on vulnerable targets.
This repository provides a working proof-of-concept (PoC) exploit for CVE-2025-29306, a critical unauthenticated remote code execution (RCE) vulnerability in FoxCMS version 1.2.5 and earlier. The vulnerability arises from unsafe deserialization of user input via the 'id' parameter in the /images/index.html endpoint, allowing attackers to inject PHP code that is executed on the server. The repository contains two exploit scripts: a Python script (CVE-2025-29306.py) and a Bash script (CVE-2025-29306.sh). Both scripts craft a malicious payload that leverages PHP's unserialize() function to execute arbitrary system commands provided by the attacker. The Python script uses the requests and lxml libraries to send the payload and parse the response, extracting command output from a specific HTML location. The Bash script uses curl and xmllint for similar functionality. The README.md provides a detailed technical breakdown, risk assessment, and mitigation advice. The exploit requires no authentication and is trivial to automate, making it highly dangerous for unpatched FoxCMS installations. The main fingerprintable endpoint is /images/index.html, which is targeted with a crafted 'id' parameter.
This repository provides proof-of-concept (PoC) exploit code for CVE-2025-29306, a critical unauthenticated remote code execution (RCE) vulnerability in FoxCMS version 1.2.5 and earlier. The vulnerability arises from unsafe deserialization of user-supplied input in the 'id' parameter of the /images/index.html endpoint, allowing attackers to execute arbitrary system commands on the server without authentication. The repository contains two exploit scripts: - CVE-2025-29306.py: A Python script that crafts a malicious payload, sends it to the vulnerable endpoint, and parses the HTML response to extract and display the output of the executed command. - CVE-2025-29306.sh: A Bash script that performs similar actions using curl and xmllint, suitable for quick command-line exploitation. Both scripts require the attacker to specify the target URL and the command to execute. The payload leverages PHP's unserialize() function to trigger command execution. The README.md provides a detailed technical breakdown, risk assessment, and mitigation advice. The exploit is unauthenticated, works remotely, and is easy to automate, making it highly dangerous for unpatched FoxCMS installations.
This repository is an educational lab simulating the core vulnerability behind CVE-2025-29306 (FoxCMS-style RCE). It contains a minimal PHP web application (public/images/index.php) that is intentionally vulnerable to remote code execution via unsafe use of unserialize() on attacker-controlled input, followed by eval(). The Dockerfile sets up a PHP 8.2 Apache environment, and entrypoint.sh generates a random flag in /opt/flag.txt at container startup. The exploit.sh script sends a specially crafted serialized PHP string as a URL-encoded 'id' parameter to the vulnerable endpoint, causing the server to execute arbitrary PHP code (in this case, reading the flag file). The repository structure is clear: Dockerfile and entrypoint.sh for environment setup, public/images/index.php as the vulnerable app, exploit.sh as the exploit script, and README.md for instructions. The main exploit capability is remote code execution via a network-accessible PHP endpoint, exploiting unsafe deserialization and code evaluation. The repository is a proof-of-concept and not weaponized, intended for educational purposes.
This repository contains a Python proof-of-concept exploit for CVE-2025-29306, a remote code execution vulnerability in FoxCMS v1.2.5. The main file, POC.py, allows an attacker to send a specially crafted payload to the 'id' parameter of the vulnerable 'index.html' component, resulting in arbitrary command execution on the server. The script supports both single-target and batch modes (via a file of URLs), using multithreading for efficiency. The exploit works by injecting a payload that leverages PHP-like code execution, and then parses the HTML response to extract and display the command output. The README provides usage instructions and an example vulnerable endpoint. No detection-only scripts are present; the code is a functional exploit. The repository is straightforward, with one exploit script and a brief README.
This repository provides a Python proof-of-concept exploit for CVE-2025-29306, a remote code execution (RCE) vulnerability in FoxCMS. The main script, 'CVE-2025-29306-PoC.py', allows an attacker to test single or multiple FoxCMS targets (specified as IP:port) for the vulnerability. The exploit works by sending a specially crafted GET request to the '/images/index.html' endpoint of the target, injecting a payload via the 'id' parameter that triggers command execution on the server. The script supports multi-threaded scanning, real-time output, and saves results to 'foxcms_rce_results.txt'. The repository also includes a README with usage instructions, a requirements.txt for dependencies, and an MIT license. The exploit is operational, allowing arbitrary command execution on vulnerable FoxCMS instances, and is suitable for both targeted and bulk exploitation scenarios.
This repository provides a Python proof-of-concept (PoC) exploit for CVE-2025-29306, a remote code execution (RCE) vulnerability in FOXCMS v1.2. The exploit targets the 'id' parameter of the /images/index.html endpoint, which is vulnerable to PHP code injection via specially crafted payloads using the '${@print()}' syntax. The main script, CVE_2025_29306.py, generates a variety of PHP payloads that attempt to execute system commands, read sensitive files, or drop webshells/backdoors on the target server. The script takes a target URL ending with '?id=' as input and iteratively injects each payload, reporting the HTTP response for each attempt. The repository consists of the exploit script and a README.md that documents the vulnerability, usage instructions, and legal disclaimer. The exploit is a functional PoC and does not include advanced features such as automated shell retrieval or post-exploitation modules.
This repository provides a proof-of-concept (POC) exploit for CVE-2025-29306, a remote code execution vulnerability in FoxCMS v1.2.5. The repository contains two files: a Bash script (CVE-2025-29306.sh) and a README.md. The Bash script is the main exploit and requires two arguments: the target URL and the command to execute. It crafts a payload that leverages PHP code injection via the 'id' parameter on the /images/index.html endpoint. The script encodes the payload, sends it to the target using curl, and extracts the command output from the HTML response using xmllint and sed. The README provides usage instructions, a Fofa dork for finding vulnerable targets, and legal disclaimers. The exploit is a POC and demonstrates the ability to execute arbitrary commands on vulnerable FoxCMS installations exposed to the internet.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.