EIP-2026-109502
PRE-CVEMKPortal 1.0/1.1 - 'admin.php' Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109502. PoCs published by Demential.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in MKPortal by tricking an administrator into executing a malicious SWF file. The SWF file sends a POST request to save permissions, granting administrative access to guests, which can then be used to upload a PHP shell.
Description
MKPortal 1.0/1.1 - 'admin.php' Authentication Bypass
Exploits (1)
This exploit leverages an authentication bypass vulnerability in MKPortal by tricking an administrator into executing a malicious SWF file. The SWF file sends a POST request to save permissions, granting administrative access to guests, which can then be used to upload a PHP shell.