Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-102308. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This advisory details a code execution vulnerability in WebDisk+ v2.1 iOS, where the `name` input field in the upload module (`afupload.ma`) allows remote attackers to execute arbitrary code via manipulated GET requests. The vulnerability is triggered through the `p` and `filename` parameters, with execution occurring in the `afgetdir.ma` file.
Description
WebDisk+ 2.1 iOS - Code Execution
Exploits (1)
This advisory details a code execution vulnerability in WebDisk+ v2.1 iOS, where the `name` input field in the upload module (`afupload.ma`) allows remote attackers to execute arbitrary code via manipulated GET requests. The vulnerability is triggered through the `p` and `filename` parameters, with execution occurring in the `afgetdir.ma` file.