EIP-2026-108035
PRE-CVEJAKCMS PRO 2.2.6 - 'uploader.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108035. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in JAKCMS PRO by leveraging a directory traversal technique in the 'catID' parameter to upload a malicious file ('lo.php') to a writable directory. The exploit uses cURL to send a POST request with the file data and manipulated path.
Description
JAKCMS PRO 2.2.6 - 'uploader.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in JAKCMS PRO by leveraging a directory traversal technique in the 'catID' parameter to upload a malicious file ('lo.php') to a writable directory. The exploit uses cURL to send a POST request with the file data and manipulated path.