
PoC in Python 3 per CVE-2026-102427, un RCE tramite upload non autenticato in OrdaSoft Joomla CCK (com_os_cck) via task=getContent e site/uploader.php utilizzando un polyglot GIF/PHP.
PoC in Python 3 per CVE-2026-102427 — OrdaSoft Joomla CCK — RCE non autenticato tramite task=getContent → site/uploader.php (polyglot GIF/PHP, nome file .php).
| CVE.org | https://www.cve.org/CVERecord?id=CVE-2026-102427 (PUBBLICATO 2026-09-30) |
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-102427 |
| CNA | Joomla! Project |
| Componente | com_os_cck |
| Affetto | 1.0.0 – 8.3.15 |
| Fix | ≥ 8.3.16 |
| CWE | CWE-434 |
| CVSS 4.0 | 10.0 Critico — AT:N |
Il front-end task=getContent raggiunge site/uploader.php senza autenticazione. Il controllo dei magic byte dell'immagine passa su un polyglot; l'estensione deriva dal nome file fornito dall'attaccante (allow-list commentata nel sorgente). La PoC carica il file locale up.php (header GIF + PHP) e verifica POCBIT-102427-OK tramite HTTP GET sul percorso restituito.
pip install requests urllib3 coloramacd CVE-2026-102427
python poc.py
python poc.py hits.txt
python poc.py --check fofa_hosts.txt
python poc.py -u https://site.tld
python poc.py --lab
python _engine.py --help
Solo per test di sicurezza autorizzati.