EIP-2026-111112
PRE-CVEphpList 2.10.2 - 'GLOBALS[]' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111112. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets PHPList <= 2.10.2 by leveraging the register_globals=On setting to inject arbitrary code into log files and execute commands via file inclusion. It demonstrates a remote command execution vulnerability by manipulating GLOBALS[] variables to include malicious log entries.
Description
phpList 2.10.2 - 'GLOBALS[]' Remote Code Execution
Exploits (1)
This exploit targets PHPList <= 2.10.2 by leveraging the register_globals=On setting to inject arbitrary code into log files and execute commands via file inclusion. It demonstrates a remote command execution vulnerability by manipulating GLOBALS[] variables to include malicious log entries.