Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109171. PoCs published by Haboob Team.
AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in LiteCart 2.1.2 by bypassing Content-Type restrictions to upload a malicious PHP file, achieving remote code execution. It authenticates as an admin, uploads a PHP shell disguised as an XML file, and executes commands via HTTP requests.
Description
LiteCart 2.1.2 - Arbitrary File Upload
Exploits (1)
This exploit leverages an arbitrary file upload vulnerability in LiteCart 2.1.2 by bypassing Content-Type restrictions to upload a malicious PHP file, achieving remote code execution. It authenticates as an admin, uploads a PHP shell disguised as an XML file, and executes commands via HTTP requests.