EIP-2026-106976
PRE-CVEExtCalendar2 - Cookie Authentication Bypass / Backdoor Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106976. PoCs published by Lagripe-Dz.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in ExtCalendar2 by manipulating cookie values, followed by uploading a PHP backdoor through file upload functionality. It achieves remote command execution by leveraging misconfigured file extension settings.
Description
ExtCalendar2 - Cookie Authentication Bypass / Backdoor Upload
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in ExtCalendar2 by manipulating cookie values, followed by uploading a PHP backdoor through file upload functionality. It achieves remote command execution by leveraging misconfigured file extension settings.