EIP-2026-111076
PRE-CVEPHPInclude.Worm - PHP Scripts Automated Arbitrary File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111076. PoCs published by anonymous.
AI-analyzed exploit summary This Perl script automates the discovery of vulnerable PHP endpoints via Google and Yahoo search queries, then attempts to exploit them by injecting a command that downloads and executes a malicious Perl script from a remote server.
Description
PHPInclude.Worm - PHP Scripts Automated Arbitrary File Inclusion
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by anonymous · perlwebappsphp
https://www.exploit-db.com/exploits/725
This Perl script automates the discovery of vulnerable PHP endpoints via Google and Yahoo search queries, then attempts to exploit them by injecting a command that downloads and executes a malicious Perl script from a remote server.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target:
PHP-based web applications with vulnerable parameters
No auth needed
Prerequisites:
Internet access · Vulnerable PHP endpoints with injectable parameters
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026