EIP-2026-106809
PRE-CVEEJ3 TOPo 2.2 - 'descripcion' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106809. PoCs published by Hessam-x.
AI-analyzed exploit summary This Perl script exploits a remote code execution vulnerability in EJ3 TOPO <= 2.1 by injecting arbitrary commands into the 'descripcion' parameter during user profile editing. It creates a user account, then abuses the profile update functionality to execute system commands via PHP code injection.
Description
EJ3 TOPo 2.2 - 'descripcion' Remote Command Execution
Exploits (1)
This Perl script exploits a remote code execution vulnerability in EJ3 TOPO <= 2.1 by injecting arbitrary commands into the 'descripcion' parameter during user profile editing. It creates a user account, then abuses the profile update functionality to execute system commands via PHP code injection.