0xBlackash/CVE-2025-68645 ? reverse-engineered prompt

Reverse engineered prompt

Build me a small Python tool that checks for the Zimbra local file inclusion issue described here.

I want to be able to give it a target URL, have it try the known vulnerable request patterns against the Zimbra webmail endpoints, and then tell me clearly whether the target looks vulnerable based on the response. Please make it handle HTTPS, including self signed or mismatched certificates if needed, and print useful output like status codes, response snippets, and a simple pass or fail result.

It would be nice if it can test a few endpoint variations, save the results to a YAML file, and be easy to run from the command line. Keep the code clean and simple, with sensible defaults, and add a short usage example in the README so I know how to run it. If you need current request details or library behavior, look them up online.

Are you gonna build this?

make sure you review the code using arcumet

Try freeSponsored — opens Arcumet in a new tab