Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111832. PoCs published by securfrog.
AI-analyzed exploit summary The provided text describes an arbitrary file-upload vulnerability in RunCMS, allowing attackers to execute arbitrary code in the context of the webserver process. It references a BID (Bugtraq ID) and a GitLab link to a PHP exploit but does not include actual exploit code.
Description
RunCMS 1.x - Avatar Arbitrary File Upload
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by securfrog · textwebappsphp
https://www.exploit-db.com/exploits/28896
The provided text describes an arbitrary file-upload vulnerability in RunCMS, allowing attackers to execute arbitrary code in the context of the webserver process. It references a BID (Bugtraq ID) and a GitLab link to a PHP exploit but does not include actual exploit code.
Classification
Writeup 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:
RunCMS (version unspecified)
No auth needed
Prerequisites:
Access to the file upload functionality in RunCMS
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026