Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-106135. PoCs published by plucky.
AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in Constructr CMS 3.03 by sending a POST request to /backend/media.php with a file attachment, bypassing restrictions to achieve remote code execution (RCE). The script parses the response to retrieve the uploaded file's new name and prints its location.
Description
Constructr CMS 3.03 - Arbitrary File Upload
Exploits (1)
This Perl script exploits an arbitrary file upload vulnerability in Constructr CMS 3.03 by sending a POST request to /backend/media.php with a file attachment, bypassing restrictions to achieve remote code execution (RCE). The script parses the response to retrieve the uploaded file's new name and prints its location.