Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102427 — Python 3 PoC for CVE-2026-102427, an unauthenticated upload RCE in OrdaSoft Joomla CCK (com_os_cck) via task=getContent and site/uploader.php using a GIF/PHP polyglot. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-102427
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRemote Access ToolPayload Development
GitHubmurrez/cve-2026-102427

CVE-2026-102427

Python 3 PoC for CVE-2026-102427, an unauthenticated upload RCE in OrdaSoft Joomla CCK (com_os_cck) via task=getContent and site/uploader.php using a GIF/PHP polyglot.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-102427 — OrdaSoft OS CCK (com_os_cck) unauthenticated upload RCE

Python 3 PoC for CVE-2026-102427 — OrdaSoft Joomla CCK — unauthenticated RCE via task=getContent → site/uploader.php (GIF/PHP polyglot, .php filename).

CVE.orghttps://www.cve.org/CVERecord?id=CVE-2026-102427 (PUBLISHED 2026-09-30)
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-102427
CNAJoomla! Project
Componentcom_os_cck
Affected1.0.0 – 8.3.15
Fix≥ 8.3.16
CWECWE-434
CVSS 4.010.0 Critical — AT:N

Mechanism

Front-end task=getContent reaches site/uploader.php with no auth. Magic-byte image check passes on a polyglot; extension comes from the attacker filename (allow-list commented out in source). PoC uploads local up.php (GIF header + PHP) and verifies POCBIT-102427-OK via HTTP GET on the returned path.

Requirements

  • Python 3.9+
  • pip install requests urllib3 colorama

Usage

cd CVE-2026-102427
python poc.py
python poc.py hits.txt
python poc.py --check fofa_hosts.txt
python poc.py -u https://site.tld
python poc.py --lab
python _engine.py --help

Legal

Authorized security testing only.

Download Tool