EIP-2026-111300

PRE-CVE

Piwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111300. PoCs published by boecke.

AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in Piwik's open-flash-chart library, allowing arbitrary PHP code execution via unsanitized user input in the 'name' parameter and direct file write via HTTP_RAW_POST_DATA.

Description

Piwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by boecke · textwebappsphp
https://www.exploit-db.com/exploits/9962

This exploit demonstrates a remote file upload vulnerability in Piwik's open-flash-chart library, allowing arbitrary PHP code execution via unsanitized user input in the 'name' parameter and direct file write via HTTP_RAW_POST_DATA.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Piwik (all versions using open-flash-chart) and other software using the vulnerable library
No auth needed
Prerequisites: Network access to the vulnerable Piwik instance · open-flash-chart library with vulnerable ofc_upload_image.php present
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026