Sploitus

Exploit for Code Injection in Ispconfig

githubexploit Β· 2025-05-02

Exploit Code

README38 lines
## https://sploitus.com/exploit?id=03A00B01-C019-5110-94A2-FA1FD1FF034C
# CVE-2023-46818 
ISPConfig - PHP Code Injection PoC Exploit (Bash)

 

    
  CVE-2023-46818 
  Authenticated PHP Code Injection in ISPConfig 
  for more details:  advisory 
  


![CVE-2023-46818 PoC](https://www.zyenra.com/assets/img/CVE-2023-46818-poc.png)


### Introduction 

`ISPConfig` versions 

### Usage 

```bash
git clone https://github.com/rvizx/CVE-2023-46818
cd CVE-2023-46818
chmod +x exploit.sh
./exploit.sh   
```


Note: This exploit requires valid ISPConfig admin credentials and will deploy a command web shell accessible at `/admin/sh.php`. It provides a terminal-like interface for continuous command execution on the target system.



### Credits

Researcher: Egidio Romano (aka EgiX) | [n0b0d13s[at]gmail[dot]com] 
Original Advisory: https://karmainsecurity.com/KIS-2023-13