Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-54420-LiteSpeed-Symlink-Exploit — CVE-2026-54420 的 PoC:通过 cPanel/WHM 中 LiteSpeed 插件的符号链接进行利用。 | Kitploit
工具/GitHubGitHub/fevar54/cve-2026-54420-litespeed-symlink-exploit
权限提升漏洞分析漏洞利用Web安全云安全学习与教育
GitHubfevar54/cve-2026-54420-litespeed-symlink-exploit

CVE-2026-54420-LiteSpeed-Symlink-Exploit

CVE-2026-54420 的 PoC:通过 cPanel/WHM 中 LiteSpeed 插件的符号链接进行利用。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
1113个月前尚未审核

CVE-2026-54420 - LiteSpeed cPanel 插件符号链接权限提升

Security Rating CVSS CISA KEV CWE

⚠️ 警告

此代码仅用于教育目的和授权的安全测试。 未经明确许可对系统进行未授权使用是违法的。

📋 描述

CVE-2026-54420 是 LiteSpeed 用于 cPanel(版本 < 2.4.8)和 WHM(版本 < 5.3.2.0)的插件中的一个符号链接(symlink)权限提升漏洞。在使用 CloudLinux/CageFS 的共享托管服务器上,拥有 FTP 或 web shell 访问权限的用户可以创建恶意符号链接,以读取其分配目录之外的文件,包括:

  • /etc/passwd, /etc/shadow
  • 其他用户的配置
  • 数据库文件
  • SSH 密钥
  • 服务器配置

技术细节

字段值
CVECVE-2026-54420
CVSS8.5 (HIGH)
VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE61 - UNIX Symbolic Link (Symlink) Following
产品LiteSpeed cPanel Plugin / WHM Plugin
版本< 2.4.8 / < 5.3.2.0
环境使用 CloudLinux/CageFS 的共享托管
利用情况已在野外确认(2026 年 5 月)

🎯 受影响版本

产品受影响版本修复版本
LiteSpeed cPanel Plugin< 2.4.82.4.8+
LiteSpeed WHM Plugin< 5.3.2.05.3.2.0+

🔧 安装

# Clonar repositorio
git clone https://github.com/username/CVE-2026-54420-LiteSpeed-Symlink-Exploit
cd CVE-2026-54420-LiteSpeed-Symlink-Exploit

# Instalar dependencias
pip install -r requirements.txt

# Dar permisos
chmod +x litespeed_symlink_exploit.py
下载工具