Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-7448 PoC — CMS Made Simple 安全漏洞

Source
Associated Vulnerability
Title:CMS Made Simple 安全漏洞 (CVE-2018-7448)
Description:CMS Made Simple(CMSMS)是CMSMS团队开发的一套开源的内容管理系统(CMS)。该系统支持基于角色的权限管理系统、基于向导的安装与更新机制、智能缓存机制等。 CMSMS 2.1.6版本中的/cmsms-2.1.6-install.php/index.php文件存在远程代码执行漏洞。远程攻击者可借助‘timezone’参数利用该漏洞注入任意的PHP代码。
Description
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
Readme
# exploit-cve-2018-7448

### Purpose
This is a python script to automate CMS Made Simple 2.1.6 - Remote Code Execution - CVE-2018-7448.

It was created based on https://www.exploit-db.com/exploits/44192.

### Usage
```bash
python3 exploit-CVE-2018-7448.py -t 127.0.0.1/cmsms -d cms -u root -p password
```

### Troubleshooting
If the installer is different from `cmsms-2.1.6-install.php`, you will have to change the file name in the code.

The exploit works on HTTP by default, if you need to exploit HTTPS, change the URLs in the code.
File Snapshot

[4.0K] /data/pocs/9e6edc0f3ad227c36ab0c2a1679356b666cd05d2 ├── [5.6K] exploit-CVE-2018-7448.py └── [ 538] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.