EIP-2026-110352
PRE-CVEosCMax 2.0 - 'FCKeditor' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110352. PoCs published by ITSecTeam.
AI-analyzed exploit summary This is a writeup describing a file upload vulnerability in osCMax 2.0 due to incomplete extension filtering in FCKeditor. The exploit suggests uploading files with extensions like .php3, which are not blocked by the default configuration.
Description
osCMax 2.0 - 'FCKeditor' Arbitrary File Upload
Exploits (1)
exploitdb
WRITEUP
by ITSecTeam · textwebappsphp
https://www.exploit-db.com/exploits/11771
This is a writeup describing a file upload vulnerability in osCMax 2.0 due to incomplete extension filtering in FCKeditor. The exploit suggests uploading files with extensions like .php3, which are not blocked by the default configuration.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
osCMax 2.0 with FCKeditor
No auth needed
Prerequisites:
Access to the FCKeditor file upload interface
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026