EIP-2026-107788
PRE-CVEimacs CMS 0.3.0 - Unrestricted Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107788. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit targets an unrestricted file upload vulnerability in imacs CMS version 0.3.0, allowing an attacker to upload a malicious PHP file and execute arbitrary commands via a reverse shell. The exploit leverages a lack of authentication and improper file extension checks in the `/src/assets/mng/mng.php` endpoint.
Description
imacs CMS 0.3.0 - Unrestricted Arbitrary File Upload
Exploits (1)
This exploit targets an unrestricted file upload vulnerability in imacs CMS version 0.3.0, allowing an attacker to upload a malicious PHP file and execute arbitrary commands via a reverse shell. The exploit leverages a lack of authentication and improper file extension checks in the `/src/assets/mng/mng.php` endpoint.