Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-46818 — CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash) | Kitploit
Tools/GitHubGitHub/rvzsec/cve-2023-46818
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubrvzsec/cve-2023-46818

CVE-2023-46818

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

View Repository
441 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-46818

ISPConfig - PHP Code Injection PoC Exploit (Bash)



langfile-injection

CVE-2023-46818
Authenticated PHP Code Injection in ISPConfig
for more details: advisory

CVE-2023-46818 PoC

Introduction

ISPConfig versions <= 3.2.11 are vulnerable to an authenticated PHP code injection vulnerability via the records[] parameter in the /admin/language_edit.php endpoint. A malicious authenticated admin user can exploit this to inject arbitrary PHP code, leading to remote code execution. The vulnerability occurs due to unsanitized handling of language file input used in dynamically generated PHP code.


Usage

git clone https://github.com/rvizx/CVE-2023-46818
cd CVE-2023-46818
chmod +x exploit.sh
./exploit.sh <target> <username> <password>

Note: This exploit requires valid ISPConfig admin credentials and will deploy a command web shell accessible at `/admin/sh.php`. It provides a terminal-like interface for continuous command execution on the target system.


Credits

Researcher: Egidio Romano (aka EgiX) | [n0b0d13s[at]gmail[dot]com]
Original Advisory: https://karmainsecurity.com/KIS-2023-13

Download Tool