EIP-2026-100017

PRE-CVE

PHP-Nuke 8.2 - Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100017. PoCs published by Net.Edit0r.

AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in PHPnuke 8.2 via the FCKeditor component. It allows an attacker to upload malicious files (e.g., PHP shells) by manipulating the file upload form and bypassing restrictions.

Description

PHP-Nuke 8.2 - Arbitrary File Upload

Exploits (1)

exploitdb WORKING POC
by Net.Edit0r · htmlwebappsaix
https://www.exploit-db.com/exploits/14058

This exploit leverages an arbitrary file upload vulnerability in PHPnuke 8.2 via the FCKeditor component. It allows an attacker to upload malicious files (e.g., PHP shells) by manipulating the file upload form and bypassing restrictions.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PHPnuke 8.2
No auth needed
Prerequisites: Target must have FCKeditor integrated with PHPnuke 8.2 · File upload functionality must be accessible
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026