Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-112211. PoCs published by DaOne.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Slash CMS, including an unrestricted file upload leading to RCE and SQL injection/XSS via crafted HTTP requests. The file upload allows arbitrary PHP files to be uploaded to /tmp/, while the SQLi/XSS exploits leverage the 'id' parameter in the 'sl_pages' module.
Description
Slash CMS - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Slash CMS, including an unrestricted file upload leading to RCE and SQL injection/XSS via crafted HTTP requests. The file upload allows arbitrary PHP files to be uploaded to /tmp/, while the SQLi/XSS exploits leverage the 'id' parameter in the 'sl_pages' module.