Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

Β·Β·FeedsΒ·ContactΒ·PrivacyΒ·Β© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kikechans/-pluck-cms-rce-cve-2023-50564
Payload GenerationExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education
GitHubkikechans/-pluck-cms-rce-cve-2023-50564

-Pluck-CMS-RCE-CVE-2023-50564

πŸ“¦ Pluck CMS 4.7.18 - Authenticated RCE Exploit (CVE-2023-50564). Bypass de restricciones de subida y ejecuciΓ³n remota. 🎯

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
View Repository
87 months agoNot yet reviewed
Share

exploit.py 🐍πŸ’₯

⚠️ Legal / ethical notice: this script is only for authorized environments βœ… (CTFs, labs, pentesting with permission). Do not use it against systems without authorization ❌.

🧾 What does this script do?

exploit_greenhorn.py automates a typical exploitation chain on a web panel:

βœ… Logs into the panel (valid password required) βœ… Creates a ZIP in memory (without writing local files) πŸ“¦ βœ… Inserts a rev.php with a reverse shell inside πŸ”πŸš βœ… Uploads the ZIP as a "module" to the panel πŸ§©β¬†οΈ βœ… "Detonates" the payload by opening the uploaded PHP URL πŸš€

πŸ“Œ The module name is randomly generated to avoid conflicts (e.g.: abcdefg, xqpmzui, etc.) 🎲

🧰 Requirements

Python 3.8+ 🐍

Dependency: requests πŸ“Œ

Installation: install the requests library with pip (pip install requests) βœ…

βš™οΈ Configuration (IMPORTANT πŸ”§)

Inside the script there is a "TUS DATOS" section that you must adjust:

RHOST_DOMAIN 🌐 β†’ target URL (include http:// or https://)

LHOST_IP 🧭 β†’ your IP where you want to receive the shell (usually the VPN/tun0 one)

LHOST_PORT πŸ”Œ β†’ port you will listen on

PASSWORD πŸ”‘ β†’ panel password (the script does not brute force)

βœ… Tip: the most common failure is LHOST_IP (put the correct IP of your VPN interface) πŸ˜…

🎧 Listener (before running)

Before launching the exploit, open a listener to receive the reverse shell πŸ‘‚πŸš

Example: netcat listening on the same port you set in LHOST_PORT (e.g. 4444). If you are not listening, nothing arrives πŸ“­.

▢️ Usage

Configure RHOST_DOMAIN, LHOST_IP, LHOST_PORT and PASSWORD βœ…

Open your listener 🎧

Run the script with Python 🐍

Typical output you might see:

[] Target: http://greenhorn.htb

[] Creating clean module: xqpmzui [] Logging in... [+] Login OK. [] Uploading payload... [*] Detonating at: http://greenhorn.htb/data/modules/xqpmzui/rev.php

[+] Timeout! (Good sign, check your netcat)

😎 Note: the "Timeout! (Good sign)" is usually NORMAL βœ… Because when the PHP opens the reverse shell, the web request may "hang" while the interactive session is alive πŸ”

🧠 How does it work internally? (explained simply)

Generates a random module name 🎲

Creates a ZIP in memory πŸ“¦ (flat structure, no internal folders)

Inside it places rev.php with a reverse shell that connects to your LHOST_IP:LHOST_PORT πŸ“‘

Logs in at /login.php πŸ”‘ (includes Referer for compatibility)

Uploads the ZIP to /admin.php?action=installmodule β¬†οΈπŸ§©

Executes the payload by accessing /data/modules/<module_name>/rev.php πŸš€πŸš

πŸ§ͺ Troubleshooting (if something fails)

❌ Login failed

Check PASSWORD πŸ”‘

Confirm that the endpoint is /login.php

Sometimes in labs you need to restart the machine/service πŸ”„

❌ Shell does not arrive

Verify LHOST_IP 🧭 (the correct IP, usually tun0)

Confirm you are listening on the correct port πŸ”ŒπŸŽ§

Try another port if there is filtering (e.g. 443 or 9001) 🚧

❌ 404 when detonating

The module may not have been installed 🧩

Some installations change paths; check the /data/modules/ structure πŸ“

πŸ›‘οΈ Notes

No ZIP left on local disk (everything is in memory) βœ…

Imports sys but does not use it (you can clean it up if you want) 🧹

Use it wisely πŸ§ πŸ˜„

βœ… Final disclaimer

No warranty. For educational and authorized use only. If you use it without permission, it's your responsibility πŸš«βš–οΈ

Download Tool