Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104137. PoCs published by Chung-chieh Shan.
AI-analyzed exploit summary This exploit demonstrates a security-bypass vulnerability in Xpdf where a maliciously crafted filename can lead to unintended file deletion due to improper handling of filenames with spaces and quotes. The PoC shows how a victim file can be removed by exploiting Xpdf's error handling and shell command injection.
Description
Xpdf 3.02-13 - 'zxpdf' Security Bypass
Exploits (1)
This exploit demonstrates a security-bypass vulnerability in Xpdf where a maliciously crafted filename can lead to unintended file deletion due to improper handling of filenames with spaces and quotes. The PoC shows how a victim file can be removed by exploiting Xpdf's error handling and shell command injection.