EIP-2026-104193
PRE-CVECayin Content Management Server 11.0 - Remote Command Injection (root)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104193. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authenticated remote command injection vulnerability in Cayin Content Management Server 11.0 via the 'NTP_Server_IP' parameter in system.cgi. The PoC uses a crafted HTTP POST request to inject a command that triggers a wget request to an external server, confirming command execution.
Description
Cayin Content Management Server 11.0 - Remote Command Injection (root)
Exploits (1)
This exploit demonstrates an authenticated remote command injection vulnerability in Cayin Content Management Server 11.0 via the 'NTP_Server_IP' parameter in system.cgi. The PoC uses a crafted HTTP POST request to inject a command that triggers a wget request to an external server, confirming command execution.