Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-35885 PoC — CloudPanel 安全漏洞

Source
Associated Vulnerability
Title: CloudPanel 安全漏洞 (CVE-2023-35885)
Description:CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
Description
CloudPanel 2 Remote Code Execution Exploit
Readme
# CloudPanel 2 Exploitation Tool (CVE-2023-35885)

This tool targets a vulnerability in CloudPanel 2 versions prior to 2.3.1. The flaw resides in the insecure file-manager cookie authentication, which can be exploited to achieve Remote Code Execution (RCE) with root privileges.

## Vulnerability Details

For comprehensive details regarding this vulnerability, please refer to the official CVE listing:
[CVE-2023-35885](https://nvd.nist.gov/vuln/detail/CVE-2023-35885)

Description from NVD:
> CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication leading to Remote Code Execution as root.

## Usage

1. **Single URL Mode**: 
    ```
    python3.10 exploit.py -u https://TARGET_URL:PORT
    ```
    This mode will check the vulnerability on a single URL and if successful, will drop you into an interactive shell.

2. **File Mode**:
    ```
    python3.10 exploit.py -f file_with_urls.txt
    ```
    This mode allows you to check multiple URLs at once. Each line in the file should contain one URL.

3. **Output Vulnerable URLs to File**:
    ```
    python3.10 exploit.py -f file_with_urls.txt -o output.txt
    ```
    Use the `-o` flag to write vulnerable URLs to an output file.

4. **Threads**:
    ```
    python3.10 exploit.py -f file_with_urls.txt -t 20
    ```
    Adjust the number of threads for concurrent testing using the `-t` flag. The default is 10.

## Disclaimer

This tool is intended for educational and research purposes only. Do not use it against any system without explicit permission. The author or any associated parties are not responsible for any misuse or damage resulting from the use of this tool.

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →