EIP-2026-107571
PRE-CVEHedgehog-CMS 1.21 - Local File Inclusion / Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107571. PoCs published by Osirys.
AI-analyzed exploit summary This Perl script exploits a Local File Inclusion (LFI) and arbitrary PHP code writing vulnerability in Hedgedog-CMS 1.21. It bypasses admin authentication via a POST parameter and injects malicious PHP code into the configuration file to achieve remote command execution (RCE).
Description
Hedgehog-CMS 1.21 - Local File Inclusion / Remote Command Execution
Exploits (1)
This Perl script exploits a Local File Inclusion (LFI) and arbitrary PHP code writing vulnerability in Hedgedog-CMS 1.21. It bypasses admin authentication via a POST parameter and injects malicious PHP code into the configuration file to achieve remote command execution (RCE).