EIP-2026-110941

PRE-CVE

phpBB 1.0.0/2.0.10 - 'admin_cash.php' Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110941. PoCs published by evilrabbi.

AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in phpBB versions 1.0.0 to 2.0.10 by manipulating the `phpbb_root_path` parameter in `admin_cash.php` to include a malicious PHP script. The script then downloads and executes a backdoor on the target system.

Description

phpBB 1.0.0/2.0.10 - 'admin_cash.php' Remote Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by evilrabbi · cwebappsphp
https://www.exploit-db.com/exploits/676

This exploit targets a remote code execution vulnerability in phpBB versions 1.0.0 to 2.0.10 by manipulating the `phpbb_root_path` parameter in `admin_cash.php` to include a malicious PHP script. The script then downloads and executes a backdoor on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: phpBB 1.0.0 - 2.0.10
Auth required
Prerequisites: Access to admin interface · Web server hosting malicious PHP script
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026