EIP-2026-110920
PRE-CVEPhpAlbum.net 0.4.1-14_fix06 - 'var3' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110920. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates a remote command execution vulnerability in PhpAlbum.net by injecting a malicious command via the 'var3' parameter in the setup command. The payload uses 'file_put_contents' to write arbitrary content to a file, indicating improper input validation.
Description
PhpAlbum.net 0.4.1-14_fix06 - 'var3' Remote Command Execution
Exploits (1)
The exploit demonstrates a remote command execution vulnerability in PhpAlbum.net by injecting a malicious command via the 'var3' parameter in the setup command. The payload uses 'file_put_contents' to write arbitrary content to a file, indicating improper input validation.