Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-108185. PoCs published by Alessandro Groppo.
AI-analyzed exploit summary This exploit leverages PHP object injection in Joomla! versions 3.0.0 to 3.4.6 to achieve unauthenticated remote code execution by backdooring the configuration.php file. It uses a crafted payload to append an eval statement, allowing arbitrary command execution via POST requests.
Description
Joomla! 3.4.6 - Remote Code Execution
Exploits (1)
This exploit leverages PHP object injection in Joomla! versions 3.0.0 to 3.4.6 to achieve unauthenticated remote code execution by backdooring the configuration.php file. It uses a crafted payload to append an eval statement, allowing arbitrary command execution via POST requests.