EIP-2026-105972
PRE-CVECMS Gratis Indonesia - 'config.php' PHP Code Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105972. PoCs published by CWH Underground.
AI-analyzed exploit summary The exploit demonstrates a PHP code injection vulnerability in CMS Gratis Indonesia 2.2 beta 1 by injecting arbitrary PHP code via the `db_prefix` parameter during setup. The crafted POST request includes a payload that executes `phpinfo()`, proving remote code execution (RCE) is achievable.
Description
CMS Gratis Indonesia - 'config.php' PHP Code Injection
Exploits (1)
The exploit demonstrates a PHP code injection vulnerability in CMS Gratis Indonesia 2.2 beta 1 by injecting arbitrary PHP code via the `db_prefix` parameter during setup. The crafted POST request includes a payload that executes `phpinfo()`, proving remote code execution (RCE) is achievable.