Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105363. PoCs published by Li Fei.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in b2evolution 6.8.2, allowing unauthenticated users to upload malicious PHP files via a multipart/form-data POST request to the comment_post.php endpoint. The uploaded file can then be executed by accessing it directly.
Description
b2evolution 6.8.2 - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in b2evolution 6.8.2, allowing unauthenticated users to upload malicious PHP files via a multipart/form-data POST request to the comment_post.php endpoint. The uploaded file can then be executed by accessing it directly.