Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110645. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a file inclusion vulnerability in PHP Album <= 0.3.2.3, leveraging uninitialized variables and specific PHP configurations (magic_quotes_gpc=Off, register_globals=On) to execute arbitrary commands. It injects PHP code into log files and includes them via the vulnerable 'data_dir' parameter.
Description
PHP Album 0.3.2.3 - Remote Command Execution
Exploits (1)
This exploit targets a file inclusion vulnerability in PHP Album <= 0.3.2.3, leveraging uninitialized variables and specific PHP configurations (magic_quotes_gpc=Off, register_globals=On) to execute arbitrary commands. It injects PHP code into log files and includes them via the vulnerable 'data_dir' parameter.