EIP-2026-111300
PRE-CVEPiwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111300. PoCs published by boecke.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in Piwik's open-flash-chart library, allowing arbitrary PHP code execution via unsanitized user input in the 'name' parameter and direct file write via HTTP_RAW_POST_DATA.
Description
Piwik 1357 2009-08-02 - Arbitrary File Upload / Code Execution
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by boecke · textwebappsphp
https://www.exploit-db.com/exploits/9962
This exploit demonstrates a remote file upload vulnerability in Piwik's open-flash-chart library, allowing arbitrary PHP code execution via unsanitized user input in the 'name' parameter and direct file write via HTTP_RAW_POST_DATA.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Piwik (all versions using open-flash-chart) and other software using the vulnerable library
No auth needed
Prerequisites:
Network access to the vulnerable Piwik instance · open-flash-chart library with vulnerable ofc_upload_image.php present
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026