EIP-2026-108304
PRE-CVEJoomla! Component com_cgtestimonial 2.2 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108304. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file upload vulnerability in the cgTestimonial 2.2 Joomla component, allowing unauthenticated attackers to upload a malicious PHP shell via the 'usr_img' parameter. The PoC includes a Perl script that automates the upload and execution of a PHP shell, enabling remote code execution (RCE).
Description
Joomla! Component com_cgtestimonial 2.2 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates an arbitrary file upload vulnerability in the cgTestimonial 2.2 Joomla component, allowing unauthenticated attackers to upload a malicious PHP shell via the 'usr_img' parameter. The PoC includes a Perl script that automates the upload and execution of a PHP shell, enabling remote code execution (RCE).