EIP-2026-110467

PRE-CVE

PANews 2.0 - PHP Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110467. PoCs published by tjomka.

AI-analyzed exploit summary The exploit demonstrates a remote PHP code execution vulnerability in PaNews 2.0b4 via the 'showcopy' parameter in 'admin_setup.php'. It allows arbitrary PHP function execution (e.g., 'include' or 'passthru') by injecting malicious code, which is then executed via 'config.php'.

Description

PANews 2.0 - PHP Remote Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by tjomka · textwebappsphp
https://www.exploit-db.com/exploits/25145

The exploit demonstrates a remote PHP code execution vulnerability in PaNews 2.0b4 via the 'showcopy' parameter in 'admin_setup.php'. It allows arbitrary PHP function execution (e.g., 'include' or 'passthru') by injecting malicious code, which is then executed via 'config.php'.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PaNews 2.0b4
No auth needed
Prerequisites: Access to the target web application · PHP code execution functions not disabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026