EIP-2026-111085
PRE-CVEPHPizabi 0.848b C1 HFP1-3 - Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111085. PoCs published by YOUCODE.
AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in PHPizabi's chat module to achieve Remote Command Execution (RCE) by polluting log files via the User-Agent header. It bypasses the need for register_globals by using log file inclusion and timestamp manipulation.
Description
PHPizabi 0.848b C1 HFP1-3 - Remote Command Execution
Exploits (1)
This exploit leverages a Local File Inclusion (LFI) vulnerability in PHPizabi's chat module to achieve Remote Command Execution (RCE) by polluting log files via the User-Agent header. It bypasses the need for register_globals by using log file inclusion and timestamp manipulation.