EIP-2026-111144
PRE-CVEphpMyBackupPro 2.5 - Remote Command Execution / Cross-Site Request Forgery
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111144. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit demonstrates a Remote Command Execution (RCE) vulnerability in phpMyBackupPro v2.5 by injecting malicious PHP code into the configuration file via a CSRF attack. The payload leverages backtick operators to execute arbitrary OS commands, such as launching calc.exe on Windows.
Description
phpMyBackupPro 2.5 - Remote Command Execution / Cross-Site Request Forgery
Exploits (1)
The exploit demonstrates a Remote Command Execution (RCE) vulnerability in phpMyBackupPro v2.5 by injecting malicious PHP code into the configuration file via a CSRF attack. The payload leverages backtick operators to execute arbitrary OS commands, such as launching calc.exe on Windows.