## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-PADSALATUSHAL-CVE-2018-16763
# Fuel CMS 1.4.1 — удалённое выполнение кода
FUEL CMS 1.4.1 позволяет выполнять оценку PHP-кода через параметр filter в pages/select/ или параметр data в preview/. Это может привести к удалённому выполнению кода без предварительной аутентификации.
# Установка
root@kitploit:~
git clone https://github.com/Trushal2004/CVE-2018-16763.git
cd CVE-2018-16763/
python3 -m pip install -r requirements.txt
chmod +x exploit.py
./exploit.py
# Справка
root@kitploit:~
$./exploit.py --help
usage: python3 ./exploit.py -u <url>
fuel cms fuel CMS 1.4.1 - Remote Code Execution Exploit
optional arguments:
-h, --help show this help message and exit
-v, --version show the version of exploit
-u url, --url url Enter the url
EXAMPLE - python3 ./exploit.py -u http://10.10.21.74
# Демонстрация
