Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111580. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit targets PunBB <= 1.2.14, leveraging an authenticated remote code execution vulnerability by uploading a malicious avatar file containing PHP shellcode. It automates the process of logging in, changing admin settings to allow avatar uploads, and uploading a fake JPG with embedded PHP code.
Description
PunBB 1.2.14 - Remote Code Execution
Exploits (1)
This exploit targets PunBB <= 1.2.14, leveraging an authenticated remote code execution vulnerability by uploading a malicious avatar file containing PHP shellcode. It automates the process of logging in, changing admin settings to allow avatar uploads, and uploading a fake JPG with embedded PHP code.