EIP-2026-111203

PRE-CVE

PHPShell 2.4 - Session Fixation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111203. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This advisory details a session fixation vulnerability in PHPShell v2.4, where the session ID is not regenerated upon authentication, potentially allowing attackers to hijack sessions if PHP.INI is configured with session.use_only_cookies=0. The writeup includes technical analysis, exploitation steps, and prerequisites.

Description

PHPShell 2.4 - Session Fixation

Exploits (1)

exploitdb WRITEUP
by hyp3rlinx · textwebappsphp
https://www.exploit-db.com/exploits/41396

This advisory details a session fixation vulnerability in PHPShell v2.4, where the session ID is not regenerated upon authentication, potentially allowing attackers to hijack sessions if PHP.INI is configured with session.use_only_cookies=0. The writeup includes technical analysis, exploitation steps, and prerequisites.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: PHPShell v2.4
No auth needed
Prerequisites: PHP.INI setting session.use_only_cookies=0 · Valid PHPSESSID from an authenticated user
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026