EIP-2026-107063
PRE-CVEFCKEditor Core - 'FileManager test.html' Arbitrary File Upload (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107063. PoCs published by pentesters.ir.
AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in FCKeditor, allowing attackers to upload a malicious .htaccess file and a PHP shell disguised as an image to achieve remote code execution.
Description
FCKEditor Core - 'FileManager test.html' Arbitrary File Upload (2)
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by pentesters.ir · textwebappsphp
https://www.exploit-db.com/exploits/17644
This is a writeup describing an arbitrary file upload vulnerability in FCKeditor, allowing attackers to upload a malicious .htaccess file and a PHP shell disguised as an image to achieve remote code execution.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
FCKeditor (all versions)
Auth required
Prerequisites:
Access to FCKeditor file upload functionality · Ability to upload .htaccess and a malicious file
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026