
Python-3-PoC für CVE-2026-102427, eine unauthentifizierte Upload-RCE in OrdaSoft Joomla CCK (com_os_cck) über task=getContent und site/uploader.php unter Verwendung eines GIF/PHP-Polyglots.
Python-3-PoC für CVE-2026-102427 — OrdaSoft Joomla CCK — unauthentifizierte RCE über task=getContent → site/uploader.php (GIF/PHP-Polyglot, .php-Dateiname).
| CVE.org | https://www.cve.org/CVERecord?id=CVE-2026-102427 (VERÖFFENTLICHT 2026-09-30) |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-102427 |
| CNA | Joomla! Project |
| Komponente | com_os_cck |
| Betroffen | 1.0.0 – 8.3.15 |
| Fix | ≥ 8.3.16 |
| CWE | CWE-434 |
| CVSS 4.0 | 10.0 Kritisch — AT:N |
Das Front-End task=getContent erreicht site/uploader.php ohne Authentifizierung. Die Magic-Byte-Bildprüfung wird von einem Polyglot bestanden; die Erweiterung stammt aus dem vom Angreifer kontrollierten Dateinamen (Allow-List im Quellcode auskommentiert). Das PoC lädt eine lokale up.php hoch (GIF-Header + PHP) und verifiziert POCBIT-102427-OK per HTTP-GET auf dem zurückgegebenen Pfad.
pip install requests urllib3 coloramacd CVE-2026-102427
python poc.py
python poc.py hits.txt
python poc.py --check fofa_hosts.txt
python poc.py -u https://site.tld
python poc.py --lab
python _engine.py --help
Nur autorisierte Sicherheitstests.