EIP-2026-108672
PRE-CVEJoomla! Component hwdVideoShare - 'flash_upload.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108672. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in the hwdVideoShare Joomla! component (r805) by uploading a malicious file with a .vob extension and then brute-forcing the uploaded filename to locate it. The exploit leverages cURL to bypass inadequate input sanitization.
Description
Joomla! Component hwdVideoShare - 'flash_upload.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in the hwdVideoShare Joomla! component (r805) by uploading a malicious file with a .vob extension and then brute-forcing the uploaded filename to locate it. The exploit leverages cURL to bypass inadequate input sanitization.