EIP-2026-106948
PRE-CVEeWebEditor 1.x - 'WYSIWYG' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106948. PoCs published by Ma3sTr0-Dz.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in eWebEditor v1.x, allowing an attacker to upload arbitrary files (e.g., ASP scripts) by manipulating the upload endpoint and bypassing file extension restrictions. The exploit provides a direct URL path to achieve remote code execution (RCE) via a crafted filename.
Description
eWebEditor 1.x - 'WYSIWYG' Arbitrary File Upload
Exploits (1)
This exploit demonstrates a remote file upload vulnerability in eWebEditor v1.x, allowing an attacker to upload arbitrary files (e.g., ASP scripts) by manipulating the upload endpoint and bypassing file extension restrictions. The exploit provides a direct URL path to achieve remote code execution (RCE) via a crafted filename.