Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-48908 — Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and an RCE panel payload. | Kitploit
Tools/GitHubGitHub/winrarzipsexploit/cve-2026-48908
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRemote Access ToolPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
winrarzipsexploit/cve-2026-48908

CVE-2026-48908

Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and an RCE panel payload.

View Repository
15 days agoNot yet reviewed



🌐 Language / Dil

Türkçe English

📌 Özet

SP Page Builder (Joomla) — Kimlik doğrulamasız ZIP yükleme → RCE

ÜrünSP Page Builder — com_sppagebuilder (JoomShaper)
Sürüm≤ 6.6.1
Fixed6.6.2+ — upload artık admin ister
AuthUnauthenticated
VektörPOST …&task=asset.uploadCustomIcon
Fieldcustom_icon (icon-font ZIP)
Yazılan yer/media/com_sppagebuilder/assets/iconfont/<pack>/fonts/
Bypass.PHP + fonts/.htaccess

🛡️ Fix

  1. SP Page Builder 6.6.2+ güncelle
  2. /media/com_sppagebuilder/ → PHP execution kapat
  3. AllowOverride None — .htaccess engelle
  4. WAF: custom_icon ZIP POST rate-limit

📦 Kurulum

git clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
DosyaGörev
winrarzips_brand.pyCMD banner (by winrarzips)
sppb48908_core.pyExploit motoru
CVE-2026-48908-Suite.pyBatch + tek hedef CLI
CVE-2026-48908.pyTek hedef wrapper
payloads/x7-panel.phpRCE panel
requirements.txtBağımlılıklar

❌ Hedef listesi, tarama sonucu ve panel URL'leri repo'da yok.

🎯 Tek hedef

python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes

📦 Toplu (kendi listende)

python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15

🔍 FOFA

body="com_sppagebuilder"

🏷️ Hata etiketleri

patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed


📌 Summary

SP Page Builder (Joomla) — Unauthenticated ZIP upload → RCE

ProductSP Page Builder — com_sppagebuilder (JoomShaper)
Affected≤ 6.6.1
Fixed6.6.2+ — upload requires admin
AuthUnauthenticated
VectorPOST …&task=asset.uploadCustomIcon
Fieldcustom_icon (icon-font ZIP)
Write path/media/com_sppagebuilder/assets/iconfont/<pack>/fonts/
Bypass.PHP + fonts/.htaccess

🛡️ Remediation

  1. Upgrade SP Page Builder to 6.6.2+
  2. Disable PHP execution under /media/com_sppagebuilder/
  3. AllowOverride None — block .htaccess PHP registration
  4. WAF: rate-limit custom_icon ZIP uploads

📦 Setup

git clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
FileRole
winrarzips_brand.pyCMD banner (by winrarzips)
sppb48908_core.pyExploit core
CVE-2026-48908-Suite.pyBatch + single-target CLI
CVE-2026-48908.pySingle-target wrapper
payloads/x7-panel.phpRCE panel payload
requirements.txtDependencies

❌ Target lists, scan results and live panel URLs are not included.

🎯 Single target

python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes

📦 Batch (your own list)

python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15

🔍 FOFA

body="com_sppagebuilder"

🏷️ Error tags

patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed


⚠️ Authorized testing / lab use only · Yalnızca yetkili test


Telegram



Download Tool