EIP-2026-111818
PRE-CVERukovoditel 3.3.1 - Remote Code Execution (RCE)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111818. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a remote code execution (RCE) vulnerability in Rukovoditel 3.3.1 by injecting PHP code into the metadata of a JPEG file, encoding it in base64, and uploading it as a profile photo. The exploit leverages improper handling of file uploads to execute arbitrary PHP code.
Description
Rukovoditel 3.3.1 - Remote Code Execution (RCE)
Exploits (1)
This exploit demonstrates a remote code execution (RCE) vulnerability in Rukovoditel 3.3.1 by injecting PHP code into the metadata of a JPEG file, encoding it in base64, and uploading it as a profile photo. The exploit leverages improper handling of file uploads to execute arbitrary PHP code.