EIP-2026-106039
PRE-CVEcmsWorks 2.2 RC4 - 'FCKeditor' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106039. PoCs published by Stack.
AI-analyzed exploit summary This PHP script exploits a file upload vulnerability in cmsWorks 2.2 RC4 by bypassing extension checks in the FCKeditor component, allowing arbitrary PHP code execution. It uploads a malicious file with a double extension (e.g., .php.zip) and provides a shell interface for command execution.
Description
cmsWorks 2.2 RC4 - 'FCKeditor' Arbitrary File Upload
Exploits (1)
This PHP script exploits a file upload vulnerability in cmsWorks 2.2 RC4 by bypassing extension checks in the FCKeditor component, allowing arbitrary PHP code execution. It uploads a malicious file with a double extension (e.g., .php.zip) and provides a shell interface for command execution.