EIP-2026-111978
PRE-CVESendCard 3.4.0 - Unauthorized Administrative Access
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111978. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets SendCard <= 3.4.0, leveraging an authentication bypass vulnerability in admin/prepend.php to execute arbitrary commands via PHP injection, remote file inclusion, or local file inclusion. The PoC provides multiple attack vectors depending on PHP configuration settings.
Description
SendCard 3.4.0 - Unauthorized Administrative Access
Exploits (1)
This exploit targets SendCard <= 3.4.0, leveraging an authentication bypass vulnerability in admin/prepend.php to execute arbitrary commands via PHP injection, remote file inclusion, or local file inclusion. The PoC provides multiple attack vectors depending on PHP configuration settings.