EIP-2026-105258
PRE-CVEAsaancart Simple PHP Shopping Cart 0.9 - Arbitrary File Upload / SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105258. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in Simple PHP Shopping Cart 0.9: an arbitrary file upload via admin/add_cat.php (bypassing authentication with SQL injection) and a SQL injection in shop/page.php. The PoC includes HTTP requests with payloads for both issues.
Description
Asaancart Simple PHP Shopping Cart 0.9 - Arbitrary File Upload / SQL Injection
Exploits (1)
The exploit demonstrates two vulnerabilities in Simple PHP Shopping Cart 0.9: an arbitrary file upload via admin/add_cat.php (bypassing authentication with SQL injection) and a SQL injection in shop/page.php. The PoC includes HTTP requests with payloads for both issues.