EIP-2026-104156

PRE-CVE

Ajax Upload - Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104156. PoCs published by Daniel Godoy.

AI-analyzed exploit summary This is a technical writeup describing an arbitrary file upload vulnerability in Ajax Upload. The author explains how to bypass file extension restrictions by manipulating HTTP headers or using multiple extensions in the filename.

Description

Ajax Upload - Arbitrary File Upload

Exploits (1)

exploitdb WRITEUP
by Daniel Godoy · textwebappsmultiple
https://www.exploit-db.com/exploits/18431

This is a technical writeup describing an arbitrary file upload vulnerability in Ajax Upload. The author explains how to bypass file extension restrictions by manipulating HTTP headers or using multiple extensions in the filename.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Ajax Upload (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Ajax Upload endpoint · Ability to modify HTTP headers or craft filenames
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026