EIP-2026-108935

PRE-CVE

Judging Management System v1.0 - Remote Code Execution (RCE)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108935. PoCs published by Angelo Pio Amirante.

AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Judging Management System v1.0 by chaining an authentication bypass (SQL injection) with an unrestricted file upload. It uploads a malicious PHP shell and triggers a reverse shell via PowerShell.

Description

Judging Management System v1.0 - Remote Code Execution (RCE)

Exploits (1)

exploitdb WORKING POC
by Angelo Pio Amirante · pythonwebappsphp
https://www.exploit-db.com/exploits/51164

This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Judging Management System v1.0 by chaining an authentication bypass (SQL injection) with an unrestricted file upload. It uploads a malicious PHP shell and triggers a reverse shell via PowerShell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Judging Management System v1.0
No auth needed
Prerequisites: Target URL · Listening IP and port for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026