EIP-2026-106159
PRE-CVECoppermine Photo Gallery 1.0 - PHP Code Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106159. PoCs published by Berend-Jan Wever.
AI-analyzed exploit summary The writeup describes a PHP code injection vulnerability in Coppermine Photo Gallery due to insufficient sanitization of user-supplied filenames, allowing arbitrary PHP code execution when a malicious JPEG is uploaded and viewed.
Description
Coppermine Photo Gallery 1.0 - PHP Code Injection
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Berend-Jan Wever · textwebappsphp
https://www.exploit-db.com/exploits/22473
The writeup describes a PHP code injection vulnerability in Coppermine Photo Gallery due to insufficient sanitization of user-supplied filenames, allowing arbitrary PHP code execution when a malicious JPEG is uploaded and viewed.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Coppermine Photo Gallery
No auth needed
Prerequisites:
Ability to upload files to the Coppermine Photo Gallery
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026