EIP-2026-109401

PRE-CVE

Memberkit 1.0 - Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109401. PoCs published by Lo$er.

AI-analyzed exploit summary This is a writeup describing a remote file upload vulnerability in Memberkit 1.0, allowing authenticated users to upload arbitrary files (e.g., PHP shells) via the 'My Picture Album' feature. The exploit details the file path structure post-upload but lacks executable code.

Description

Memberkit 1.0 - Arbitrary File Upload

Exploits (1)

exploitdb WRITEUP VERIFIED
by Lo$er · textwebappsphp
https://www.exploit-db.com/exploits/7638

This is a writeup describing a remote file upload vulnerability in Memberkit 1.0, allowing authenticated users to upload arbitrary files (e.g., PHP shells) via the 'My Picture Album' feature. The exploit details the file path structure post-upload but lacks executable code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Memberkit 1.0
Auth required
Prerequisites: Registered and authenticated user account · Access to the 'My Picture Album' upload feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026