CVE-2023-30258 is a command injection vulnerability in MagnusBilling versions 6.x and 7.x (up to commit 7af21ed620). The flaw resides in lib/icepay/icepay.php at line 753, where user-supplied input from the GET parameter 'democ' is passed directly to the exec() function without sanitization. This allows unauthenticated remote attackers to execute arbitrary OS commands as the web server user (typically www-data). The vulnerability is present in demonstration code and can be exploited via a simple HTTP request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
Repository contains a Python PoC exploit (CVE-2023-30258.py) and a README. The exploit targets an unauthenticated command injection in Magnus Billing v7 (notably documented for v7.3.0) where the `democ` GET parameter in `/mbilling/lib/icepay/icepay.php` is passed to a shell without sanitization. Because the injection is blind (no command output in HTTP response), the script implements a pseudo-interactive shell by (1) sending `democ=;<command>;` to trigger execution, (2) redirecting stdout/stderr to a predictable file in the server webroot (`/var/www/html/mbilling/lib/icepay/out.txt`), and (3) retrieving results by HTTP GET to `/mbilling/lib/icepay/out.txt`. It verifies exploitation by running `id` and checking for `uid=` in the fetched output. On exit or Ctrl+C it attempts cleanup by removing the output file (`rm /var/www/html/mbilling/lib/icepay/out.txt`). Dependencies are `requests` and `prompt_toolkit`; the script disables TLS verification and uses a 10-second timeout for requests.
This repository contains a working exploit for CVE-2023-30258, a remote code execution vulnerability in Magnus Billing 7.3.0. The vulnerability exists in the 'democ' parameter of the icepay.php script, which is unsafely passed to the PHP exec() function, allowing arbitrary command execution via crafted GET requests. The repository includes a Python script (magnusbilling_rce.py) that automates exploitation by sending a payload to the vulnerable endpoint, resulting in a reverse shell to the attacker's machine. The script supports two types of reverse shell payloads (bash and mkfifo) and requires the attacker to specify their own IP, port, and the target URL. The README.md provides detailed usage instructions, an explanation of the vulnerability, and example payloads. The exploit is operational and provides a shell if the target is vulnerable and accessible.
This repository contains a single Python script, 'exploit.py', which targets a command injection vulnerability in Magnus Billing System v7, specifically in the 'icepay.php' script. The exploit takes as input the target IP (running the vulnerable Magnus Billing System), the attacker's IP, and a port number. It crafts a malicious payload that, when sent as a GET request parameter to the vulnerable endpoint, triggers a reverse shell from the target to the attacker's machine using netcat. The script is operational and automates the exploitation process, requiring the attacker to have a netcat listener ready. The main fingerprintable endpoint is the HTTP URL to 'icepay.php' on the target, and the payload uses a temporary file '/tmp/f' on the target system for the reverse shell. The exploit is not part of a framework and is a standalone operational exploit script.
This repository is a proof-of-concept (POC) exploit for CVE-2023-30258, targeting a command injection vulnerability in the 'mbilling' application. The exploit is implemented in Python (poc.py) and allows an attacker to execute arbitrary system commands on a vulnerable server by exploiting the 'democ' parameter in the 'lib/icepay/icepay.php' endpoint. The script takes a target URL and a command to execute as arguments, constructs a malicious request, and sends it to the target. The README provides usage instructions and an example command. The exploit is network-based and requires the attacker to know the base URL of the vulnerable application. No hardcoded payload is provided; the attacker supplies the command to execute, making this a flexible POC for remote code execution.
This repository contains a single Metasploit module targeting an unauthenticated remote command execution (RCE) vulnerability (CVE-2023-30258) in MagnusBilling application versions 6.x and 7.x (prior to commit 7af21ed620). The exploit leverages a command injection flaw in the 'lib/icepay/icepay.php' script, where the 'democ' GET parameter is unsafely passed to an exec() call. The module supports multiple payloads, including PHP and bash reverse shells, and can upload a PHP webshell disguised as a PNG image. The attack is performed over HTTP and does not require authentication. The exploit is weaponized, providing reliable remote code execution and post-exploitation capabilities. The repository structure is typical for a Metasploit module, with all logic contained in a single Ruby file under the appropriate modules/exploits path.
This repository contains a Bash exploit script (exp.sh) and a minimal README. The script targets a web application endpoint at /lib/icepay/icepay.php, exploiting a command injection vulnerability in the 'democ' parameter. The script first tests for vulnerability by timing a 'sleep 5' command, then allows the user to execute arbitrary shell commands on the target server. The exploit is operational, providing real command execution, and is designed for Linux-based web servers. The only code file is exp.sh, which is the entry point and contains all exploit logic. No specific CVE or product is referenced, but the exploit is tailored for web applications exposing the vulnerable PHP endpoint.
This repository contains a Python exploit script (exploit.py) and a detailed README.md. The exploit targets a command injection vulnerability in Magnus Billing System v7, specifically in the icepay.php script at /mbilling/lib/icepay/icepay.php. The exploit is unauthenticated and leverages the 'democ' GET parameter to inject a shell command that establishes a reverse shell to the attacker's machine using netcat. The script is configurable via command-line arguments for the target IP, attacker IP, and port. The README provides comprehensive usage instructions, prerequisites, and technical notes. The exploit is operational, providing a working reverse shell if the target is vulnerable and properly configured. The main attack vector is network-based, exploiting a web application endpoint. The only code file is exploit.py, which is the entry point for the exploit.
This repository contains a single Python proof-of-concept exploit (poc.py) targeting a command injection vulnerability in the 'mbilling' application's icepay.php script. The exploit crafts a malicious payload that, when injected via the 'democ' parameter, causes the target server to execute a bash reverse shell command. The payload is URL-encoded and sent as a GET request to the vulnerable endpoint. The attacker must specify their own IP (LHOST) and port (LPORT) to receive the reverse shell connection. The exploit is operational, providing a working reverse shell if the target is vulnerable and properly configured. The main fingerprintable endpoint is the hardcoded target URL (http://10.10.2.238/mbilling/lib/icepay/icepay.php), and the exploit uses a temporary file (/tmp/f) on the target system as part of the shell mechanism. The code is straightforward, with no framework dependencies, and is intended for direct exploitation of the identified vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.