EIP-2026-108989
PRE-CVEKemana Directory 1.5.6 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108989. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authenticated arbitrary file upload vulnerability in Kemana Directory 1.5.6, allowing remote code execution by uploading a malicious PHP script via multiple modules. The uploaded file is stored in the '/public/image/' directory and can be executed with a GET request.
Description
Kemana Directory 1.5.6 - Remote Code Execution
Exploits (1)
This exploit demonstrates an authenticated arbitrary file upload vulnerability in Kemana Directory 1.5.6, allowing remote code execution by uploading a malicious PHP script via multiple modules. The uploaded file is stored in the '/public/image/' directory and can be executed with a GET request.