Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-48908 — Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and an RCE panel payload. | Kitploit
أدوات/GitHubGitHub/winrarzipsexploit/cve-2026-48908
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRemote Access ToolPayload Development

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHub
winrarzipsexploit/cve-2026-48908

CVE-2026-48908

Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and an RCE panel payload.

عرض المستودع
منذ 14 أياملم تتم المراجعة بعد
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.



🌐 Language / Dil

Türkçe English

📌 Özet

SP Page Builder (Joomla) — Kimlik doğrulamasız ZIP yükleme → RCE

ÜrünSP Page Builder — com_sppagebuilder (JoomShaper)
Sürüm≤ 6.6.1
Fixed6.6.2+ — upload artık admin ister
AuthUnauthenticated
VektörPOST …&task=asset.uploadCustomIcon
Fieldcustom_icon (icon-font ZIP)
Yazılan yer/media/com_sppagebuilder/assets/iconfont/<pack>/fonts/
Bypass.PHP + fonts/.htaccess

🛡️ Fix

  1. SP Page Builder 6.6.2+ güncelle
  2. /media/com_sppagebuilder/ → PHP execution kapat
  3. AllowOverride None — .htaccess engelle
  4. WAF: custom_icon ZIP POST rate-limit

📦 Kurulum

git clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
DosyaGörev
winrarzips_brand.pyCMD banner (by winrarzips)
sppb48908_core.pyExploit motoru
CVE-2026-48908-Suite.pyBatch + tek hedef CLI
CVE-2026-48908.pyTek hedef wrapper
payloads/x7-panel.phpRCE panel
requirements.txtBağımlılıklar

❌ Hedef listesi, tarama sonucu ve panel URL'leri repo'da yok.

🎯 Tek hedef

python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes

📦 Toplu (kendi listende)

python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15

🔍 FOFA

body="com_sppagebuilder"

🏷️ Hata etiketleri

patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed


📌 Summary

SP Page Builder (Joomla) — Unauthenticated ZIP upload → RCE

ProductSP Page Builder — com_sppagebuilder (JoomShaper)
Affected≤ 6.6.1
Fixed6.6.2+ — upload requires admin
AuthUnauthenticated
VectorPOST …&task=asset.uploadCustomIcon
Fieldcustom_icon (icon-font ZIP)
Write path/media/com_sppagebuilder/assets/iconfont/<pack>/fonts/
Bypass.PHP + fonts/.htaccess

🛡️ Remediation

  1. Upgrade SP Page Builder to 6.6.2+
  2. Disable PHP execution under /media/com_sppagebuilder/
  3. AllowOverride None — block .htaccess PHP registration
  4. WAF: rate-limit custom_icon ZIP uploads

📦 Setup

git clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
FileRole
winrarzips_brand.pyCMD banner (by winrarzips)
sppb48908_core.pyExploit core
CVE-2026-48908-Suite.pyBatch + single-target CLI
CVE-2026-48908.pySingle-target wrapper
payloads/x7-panel.phpRCE panel payload
requirements.txtDependencies

❌ Target lists, scan results and live panel URLs are not included.

🎯 Single target

python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes

📦 Batch (your own list)

python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15

🔍 FOFA

body="com_sppagebuilder"

🏷️ Error tags

patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed


⚠️ Authorized testing / lab use only · Yalnızca yetkili test


Telegram



تنزيل الأداة