EIP-2026-106671
PRE-CVEe107 Filedownload Plugin - Arbitrary File Upload / Remote File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106671. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in the FileDownload Plugin for e107, allowing an attacker to upload a malicious PHP file and disclose local files via path traversal. The PoC uses cURL to upload a file with PHP code and accesses sensitive files through a null byte injection.
Description
e107 Filedownload Plugin - Arbitrary File Upload / Remote File Disclosure
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in the FileDownload Plugin for e107, allowing an attacker to upload a malicious PHP file and disclose local files via path traversal. The PoC uses cURL to upload a file with PHP code and accesses sensitive files through a null byte injection.