EIP-2026-106309
PRE-CVECuteNews 2.1.2 - Authenticated Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106309. PoCs published by Nhat Ha.
AI-analyzed exploit summary This exploit demonstrates an authenticated arbitrary file upload vulnerability in CuteNews 2.1.2, allowing low-privilege users (Editors) to bypass file upload restrictions and execute arbitrary commands by uploading a malicious PNG file with embedded PHP code and renaming it to a PHP extension.
Description
CuteNews 2.1.2 - Authenticated Arbitrary File Upload
Exploits (1)
This exploit demonstrates an authenticated arbitrary file upload vulnerability in CuteNews 2.1.2, allowing low-privilege users (Editors) to bypass file upload restrictions and execute arbitrary commands by uploading a malicious PNG file with embedded PHP code and renaming it to a PHP extension.