EIP-2026-109805
PRE-CVEMySQLDumper 1.24.4 - 'menu.php' PHP Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109805. PoCs published by AkaStep.
AI-analyzed exploit summary This exploit targets a file inclusion vulnerability in MySQLDumper 1.24.4, allowing remote attackers to execute arbitrary PHP code via crafted input to the 'config' parameter. The vulnerability arises from insufficient sanitization in the read_config() function, which uses eval() on user-controlled input.
Description
MySQLDumper 1.24.4 - 'menu.php' PHP Remote Code Execution
Exploits (1)
This exploit targets a file inclusion vulnerability in MySQLDumper 1.24.4, allowing remote attackers to execute arbitrary PHP code via crafted input to the 'config' parameter. The vulnerability arises from insufficient sanitization in the read_config() function, which uses eval() on user-controlled input.