EIP-2026-107219

PRE-CVE

Free PHP photo Gallery script - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107219. PoCs published by ViRuS Qalaa.

AI-analyzed exploit summary This exploit targets a command injection vulnerability in the Free PHP photo gallery script. The vulnerability exists in the `adodb-perf.inc.php` file where user-controlled input is passed to the `exec` function without proper sanitization, allowing remote command execution.

Description

Free PHP photo Gallery script - Remote Command Execution

Exploits (1)

exploitdb WORKING POC
by ViRuS Qalaa · textwebappsphp
https://www.exploit-db.com/exploits/14437

This exploit targets a command injection vulnerability in the Free PHP photo gallery script. The vulnerability exists in the `adodb-perf.inc.php` file where user-controlled input is passed to the `exec` function without proper sanitization, allowing remote command execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Free PHP photo gallery script (version unspecified)
No auth needed
Prerequisites: Target must be running the vulnerable Free PHP photo gallery script · The `adodb-perf.inc.php` file must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026