EIP-2026-110352

PRE-CVE

osCMax 2.0 - 'FCKeditor' Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110352. PoCs published by ITSecTeam.

AI-analyzed exploit summary This is a writeup describing a file upload vulnerability in osCMax 2.0 due to incomplete extension filtering in FCKeditor. The exploit suggests uploading files with extensions like .php3, which are not blocked by the default configuration.

Description

osCMax 2.0 - 'FCKeditor' Arbitrary File Upload

Exploits (1)

exploitdb WRITEUP
by ITSecTeam · textwebappsphp
https://www.exploit-db.com/exploits/11771

This is a writeup describing a file upload vulnerability in osCMax 2.0 due to incomplete extension filtering in FCKeditor. The exploit suggests uploading files with extensions like .php3, which are not blocked by the default configuration.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: osCMax 2.0 with FCKeditor
No auth needed
Prerequisites: Access to the FCKeditor file upload interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026