EIP-2026-104424
PRE-CVESeacms 11.1 - 'ip and weburl' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104424. PoCs published by j5s.
AI-analyzed exploit summary This exploit demonstrates a Remote Command Execution (RCE) vulnerability in Seacms 11.1 by injecting PHP code into the 'ip' parameter via a POST request to admin_ip.php. The payload bypasses input validation by appending a semicolon and PHP code to execute arbitrary commands.
Description
Seacms 11.1 - 'ip and weburl' Remote Command Execution
Exploits (1)
exploitdb
WORKING POC
by j5s · textwebappsmultiple
https://www.exploit-db.com/exploits/49249
This exploit demonstrates a Remote Command Execution (RCE) vulnerability in Seacms 11.1 by injecting PHP code into the 'ip' parameter via a POST request to admin_ip.php. The payload bypasses input validation by appending a semicolon and PHP code to execute arbitrary commands.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Seacms 11.1
Auth required
Prerequisites:
Access to admin_ip.php · Valid session cookies (PHPSESSID, t00ls, etc.)
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026