EIP-2026-106530
PRE-CVEDolphin 7.0.7 - 'member_menu_queries.php' Remote PHP Code Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106530. PoCs published by EgiX.
AI-analyzed exploit summary This PHP exploit demonstrates a remote PHP code injection vulnerability in Dolphin <= 7.0.7 by leveraging unsanitized input passed to eval() via the 'bubbles' parameter in member_menu_queries.php. It authenticates, injects malicious PHP code, and provides a shell for command execution.
Description
Dolphin 7.0.7 - 'member_menu_queries.php' Remote PHP Code Injection
Exploits (1)
This PHP exploit demonstrates a remote PHP code injection vulnerability in Dolphin <= 7.0.7 by leveraging unsanitized input passed to eval() via the 'bubbles' parameter in member_menu_queries.php. It authenticates, injects malicious PHP code, and provides a shell for command execution.