EIP-2026-109134
PRE-CVELightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109134. PoCs published by Maide Ilkay Aydogdu.
AI-analyzed exploit summary This Metasploit module exploits an authenticated file upload vulnerability in a lightweight PHP blog system, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit leverages CSRF token authentication and a multipart form upload to bypass restrictions.
Description
Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
Exploits (1)
This Metasploit module exploits an authenticated file upload vulnerability in a lightweight PHP blog system, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit leverages CSRF token authentication and a multipart form upload to bypass restrictions.