EIP-2026-106306
PRE-CVECuteNews 1.4.6 - 'ip ban' Authorized Cross-Site Scripting / Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106306. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit targets CuteNews <= 1.4.6 by leveraging an authenticated privilege escalation vulnerability in the IP ban feature to inject PHP code into ipban.db.php, enabling remote command execution. The PoC includes a reverse shell payload and interactive shell functionality.
Description
CuteNews 1.4.6 - 'ip ban' Authorized Cross-Site Scripting / Command Execution
Exploits (1)
This exploit targets CuteNews <= 1.4.6 by leveraging an authenticated privilege escalation vulnerability in the IP ban feature to inject PHP code into ipban.db.php, enabling remote command execution. The PoC includes a reverse shell payload and interactive shell functionality.