EIP-2026-111978

PRE-CVE

SendCard 3.4.0 - Unauthorized Administrative Access

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111978. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets SendCard <= 3.4.0, leveraging an authentication bypass vulnerability in admin/prepend.php to execute arbitrary commands via PHP injection, remote file inclusion, or local file inclusion. The PoC provides multiple attack vectors depending on PHP configuration settings.

Description

SendCard 3.4.0 - Unauthorized Administrative Access

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/2117

This exploit targets SendCard <= 3.4.0, leveraging an authentication bypass vulnerability in admin/prepend.php to execute arbitrary commands via PHP injection, remote file inclusion, or local file inclusion. The PoC provides multiple attack vectors depending on PHP configuration settings.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SendCard <= 3.4.0
No auth needed
Prerequisites: PHP with magic_quotes_gpc=Off (for action 1) · allow_url_fopen=On (for action 2) · Access to Apache logs (for action 3)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026