EIP-2026-111377
PRE-CVEPmWiki 2.1.19 - 'Zend_Hash_Del_Key_Or_Index' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111377. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in PmWiki <= 2.1.19 by leveraging a Zend_Hash_Del_Key_Or_Index issue in PHP versions < 4.4.3 or 5 <= PHP < 5.1.4 with register_globals enabled. It sends a crafted multipart/form-data POST request to execute arbitrary commands via the CLIENT-IP header.
Description
PmWiki 2.1.19 - 'Zend_Hash_Del_Key_Or_Index' Remote Command Execution
Exploits (1)
This exploit targets a remote command execution vulnerability in PmWiki <= 2.1.19 by leveraging a Zend_Hash_Del_Key_Or_Index issue in PHP versions < 4.4.3 or 5 <= PHP < 5.1.4 with register_globals enabled. It sends a crafted multipart/form-data POST request to execute arbitrary commands via the CLIENT-IP header.