EIP-2026-105925
PRE-CVEClinic's Patient Management System 1.0 - Unauthenticated RCE
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105925. PoCs published by Oğulcan Hami Gül.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in Clinic's Patient Management System 1.0. The attacker uploads a malicious PHP file disguised as a profile picture, bypassing authentication and achieving arbitrary command execution via a simple PHP backdoor.
Description
Clinic's Patient Management System 1.0 - Unauthenticated RCE
Exploits (1)
This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in Clinic's Patient Management System 1.0. The attacker uploads a malicious PHP file disguised as a profile picture, bypassing authentication and achieving arbitrary command execution via a simple PHP backdoor.