EIP-2026-109434
PRE-CVEMetInfo 3.0 - 'FCKeditor' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109434. PoCs published by [sh3n].
AI-analyzed exploit summary This PHP script exploits a file upload vulnerability in MetInfo 3.0's FCKeditor component, allowing arbitrary file upload by spoofing the file extension (e.g., .php.pdf) to bypass restrictions. It then provides a shell interface to execute commands on the target system via HTTP requests.
Description
MetInfo 3.0 - 'FCKeditor' Arbitrary File Upload
Exploits (1)
This PHP script exploits a file upload vulnerability in MetInfo 3.0's FCKeditor component, allowing arbitrary file upload by spoofing the file extension (e.g., .php.pdf) to bypass restrictions. It then provides a shell interface to execute commands on the target system via HTTP requests.