Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109224. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an unauthenticated arbitrary command execution vulnerability in Lunar CMS 3.3 by abusing the elfinder file manager's upload/create/rename functionality to write a malicious PHP script to the '/files' directory. The script then allows remote command execution via a passthru function.
Description
Lunar CMS 3.3 - Remote Command Execution
Exploits (1)
This exploit leverages an unauthenticated arbitrary command execution vulnerability in Lunar CMS 3.3 by abusing the elfinder file manager's upload/create/rename functionality to write a malicious PHP script to the '/files' directory. The script then allows remote command execution via a passthru function.