EIP-2026-110876
PRE-CVEPHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110876. PoCs published by pentesters.ir.
AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in PHP-Nuke 8.3 by bypassing file extension checks to upload a malicious PHP file disguised as a GIF. It crafts a multipart POST request to upload the file and retrieves the uploaded path for remote code execution.
Description
PHP-Nuke 8.3 - 'upload.php' Arbitrary File Upload (2)
Exploits (1)
This Perl script exploits an arbitrary file upload vulnerability in PHP-Nuke 8.3 by bypassing file extension checks to upload a malicious PHP file disguised as a GIF. It crafts a multipart POST request to upload the file and retrieves the uploaded path for remote code execution.