Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109604. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in MPS Box 0.1.8.0, allowing an attacker to upload a malicious PHP file via the device_add.php endpoint. The PoC includes steps for authentication bypass via SQL injection and file upload to achieve remote code execution.
Description
MPS Box 0.1.8.0 - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in MPS Box 0.1.8.0, allowing an attacker to upload a malicious PHP file via the device_add.php endpoint. The PoC includes steps for authentication bypass via SQL injection and file upload to achieve remote code execution.