EIP-2026-102984
PRE-CVErunAV mod_security - Arbitrary Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102984. PoCs published by R-73eN.
AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability in runAV (mod_security utility) due to unsanitized user input passed to sprintf and subsequently executed via run_cmd. The PoC shows arbitrary command execution by appending a command after a semicolon in the input argument.
Description
runAV mod_security - Arbitrary Command Execution
Exploits (1)
The exploit demonstrates a command injection vulnerability in runAV (mod_security utility) due to unsanitized user input passed to sprintf and subsequently executed via run_cmd. The PoC shows arbitrary command execution by appending a command after a semicolon in the input argument.