EIP-2026-108184
PRE-CVEJoomla! 3.4.6 - 'configuration.php' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108184. PoCs published by Alessandro Groppo.
AI-analyzed exploit summary This exploit targets a PHP object injection vulnerability in Joomla 3.0.0 to 3.4.6, allowing remote code execution by manipulating serialized objects in the login process. It implants a backdoor in the configuration.php file via an eval statement, enabling arbitrary command execution.
Description
Joomla! 3.4.6 - 'configuration.php' Remote Code Execution
Exploits (1)
This exploit targets a PHP object injection vulnerability in Joomla 3.0.0 to 3.4.6, allowing remote code execution by manipulating serialized objects in the login process. It implants a backdoor in the configuration.php file via an eval statement, enabling arbitrary command execution.