
π¦ Pluck CMS 4.7.18 - Authenticated RCE Exploit (CVE-2023-50564). Bypass de restricciones de subida y ejecuciΓ³n remota. π―
exploit.py ππ₯
β οΈ Legal / ethical notice: this script is only for authorized environments β (CTFs, labs, pentesting with permission). Do not use it against systems without authorization β.
π§Ύ What does this script do?
exploit_greenhorn.py automates a typical exploitation chain on a web panel:
β Logs into the panel (valid password required) β Creates a ZIP in memory (without writing local files) π¦ β Inserts a rev.php with a reverse shell inside ππ β Uploads the ZIP as a "module" to the panel π§©β¬οΈ β "Detonates" the payload by opening the uploaded PHP URL π
π The module name is randomly generated to avoid conflicts (e.g.: abcdefg, xqpmzui, etc.) π²
π§° Requirements
Python 3.8+ π
Dependency: requests π
Installation: install the requests library with pip (pip install requests) β
βοΈ Configuration (IMPORTANT π§)
Inside the script there is a "TUS DATOS" section that you must adjust:
RHOST_DOMAIN π β target URL (include http:// or https://)
LHOST_IP π§ β your IP where you want to receive the shell (usually the VPN/tun0 one)
LHOST_PORT π β port you will listen on
PASSWORD π β panel password (the script does not brute force)
β Tip: the most common failure is LHOST_IP (put the correct IP of your VPN interface) π
π§ Listener (before running)
Before launching the exploit, open a listener to receive the reverse shell ππ
Example: netcat listening on the same port you set in LHOST_PORT (e.g. 4444). If you are not listening, nothing arrives π.
βΆοΈ Usage
Configure RHOST_DOMAIN, LHOST_IP, LHOST_PORT and PASSWORD β
Open your listener π§
Run the script with Python π
Typical output you might see:
[] Target: http://greenhorn.htb
[] Creating clean module: xqpmzui [] Logging in... [+] Login OK. [] Uploading payload... [*] Detonating at: http://greenhorn.htb/data/modules/xqpmzui/rev.php
[+] Timeout! (Good sign, check your netcat)
π Note: the "Timeout! (Good sign)" is usually NORMAL β Because when the PHP opens the reverse shell, the web request may "hang" while the interactive session is alive π
π§ How does it work internally? (explained simply)
Generates a random module name π²
Creates a ZIP in memory π¦ (flat structure, no internal folders)
Inside it places rev.php with a reverse shell that connects to your LHOST_IP:LHOST_PORT π‘
Logs in at /login.php π (includes Referer for compatibility)
Uploads the ZIP to /admin.php?action=installmodule β¬οΈπ§©
Executes the payload by accessing /data/modules/<module_name>/rev.php ππ
π§ͺ Troubleshooting (if something fails)
β Login failed
Check PASSWORD π
Confirm that the endpoint is /login.php
Sometimes in labs you need to restart the machine/service π
β Shell does not arrive
Verify LHOST_IP π§ (the correct IP, usually tun0)
Confirm you are listening on the correct port ππ§
Try another port if there is filtering (e.g. 443 or 9001) π§
β 404 when detonating
The module may not have been installed π§©
Some installations change paths; check the /data/modules/ structure π
π‘οΈ Notes
No ZIP left on local disk (everything is in memory) β
Imports sys but does not use it (you can clean it up if you want) π§Ή
Use it wisely π§ π
β Final disclaimer
No warranty. For educational and authorized use only. If you use it without permission, it's your responsibility π«βοΈ