EIP-2026-100941
PRE-CVEZamFoo - Multiple Remote Command Execution Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100941. PoCs published by Al-Shabaab.
AI-analyzed exploit summary The exploit demonstrates command injection vulnerabilities in ZamFoo via two CGI endpoints, allowing arbitrary command execution (e.g., `rm -rf`) by manipulating the `accounttorestore` and `accounttochange` parameters. No authentication is required, and the payloads are straightforward command injection examples.
Description
ZamFoo - Multiple Remote Command Execution Vulnerabilities
Exploits (1)
The exploit demonstrates command injection vulnerabilities in ZamFoo via two CGI endpoints, allowing arbitrary command execution (e.g., `rm -rf`) by manipulating the `accounttorestore` and `accounttochange` parameters. No authentication is required, and the payloads are straightforward command injection examples.