Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111804. PoCs published by Tyrell Sassen.
AI-analyzed exploit summary The exploit demonstrates a file extension bypass vulnerability in Roxy Fileman <= 1.4.4, allowing an attacker to rename a file to a forbidden extension (e.g., .php) via the move function, which lacks proper validation. This can lead to remote code execution if the renamed file contains malicious code.
Description
Roxy Fileman 1.4.4 - Arbitrary File Upload
Exploits (1)
The exploit demonstrates a file extension bypass vulnerability in Roxy Fileman <= 1.4.4, allowing an attacker to rename a file to a forbidden extension (e.g., .php) via the move function, which lacks proper validation. This can lead to remote code execution if the renamed file contains malicious code.