EIP-2026-109450
PRE-CVEMicroweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109450. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authenticated file upload filter bypass in Microweber v1.0.3, allowing arbitrary PHP code execution by appending a dot to the filename to bypass extension restrictions. The PoC includes a multipart form upload request and a subsequent GET request to execute the uploaded PHP file.
Description
Microweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution
Exploits (1)
This exploit demonstrates an authenticated file upload filter bypass in Microweber v1.0.3, allowing arbitrary PHP code execution by appending a dot to the filename to bypass extension restrictions. The PoC includes a multipart form upload request and a subsequent GET request to execute the uploaded PHP file.