EIP-2026-110048
PRE-CVEOneOrZero helpdesk 1.6.x. - Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110048. PoCs published by Ams.
AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in OneOrZero 1.6.* via the 'tinfo.php' script, allowing an attacker to upload a malicious PHP shell. It bruteforces the uploaded shell's filename due to timestamp-based naming and then uploads a secondary shell for persistent access.
Description
OneOrZero helpdesk 1.6.x. - Arbitrary File Upload
Exploits (1)
This Perl script exploits an arbitrary file upload vulnerability in OneOrZero 1.6.* via the 'tinfo.php' script, allowing an attacker to upload a malicious PHP shell. It bruteforces the uploaded shell's filename due to timestamp-based naming and then uploads a secondary shell for persistent access.