EIP-2026-110308
PRE-CVEOpenForum 2.2 b005 - 'saveAsAttachment()' Method Arbitrary File Creation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110308. PoCs published by John Leitch.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file write vulnerability in OpenForum Server 2.2 b005 by uploading a malicious .sjs file that leverages the saveAsAttachment method to write to the server's filesystem. The PoC uses a multipart form data request to create a file in the root directory.
Description
OpenForum 2.2 b005 - 'saveAsAttachment()' Method Arbitrary File Creation
Exploits (1)
This exploit demonstrates an arbitrary file write vulnerability in OpenForum Server 2.2 b005 by uploading a malicious .sjs file that leverages the saveAsAttachment method to write to the server's filesystem. The PoC uses a multipart form data request to create a file in the root directory.