
PoC Python 3 pour CVE-2026-102427, une RCE par téléversement non authentifié dans OrdaSoft Joomla CCK (com_os_cck) via task=getContent et site/uploader.php en utilisant un polyglotte GIF/PHP.
PoC Python 3 pour CVE-2026-102427 — OrdaSoft Joomla CCK — RCE non authentifiée via task=getContent → site/uploader.php (polyglotte GIF/PHP, nom de fichier .php).
| CVE.org | https://www.cve.org/CVERecord?id=CVE-2026-102427 (PUBLIÉE 2026-09-30) |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-102427 |
| CNA | Joomla! Project |
| Composant | com_os_cck |
| Affecté | 1.0.0 – 8.3.15 |
| Correctif | ≥ 8.3.16 |
| CWE | CWE-434 |
| CVSS 4.0 | 10.0 Critique — AT:N |
Le task=getContent côté front-end atteint site/uploader.php sans authentification. La vérification des magic bytes d'image passe sur un polyglotte ; l'extension provient du nom de fichier fourni par l'attaquant (liste blanche commentée dans le code source). Le PoC téléverse le fichier local up.php (en-tête GIF + PHP) et vérifie POCBIT-102427-OK via une requête HTTP GET sur le chemin retourné.
pip install requests urllib3 coloramacd CVE-2026-102427
python poc.py
python poc.py hits.txt
python poc.py --check fofa_hosts.txt
python poc.py -u https://site.tld
python poc.py --lab
python _engine.py --help
Tests de sécurité autorisés uniquement.