EIP-2026-112714
PRE-CVETinyPHPForum 3.6 - 'UpdatePF.php' Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112714. PoCs published by SirDarckCat.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass and arbitrary file read vulnerability in TinyPHPForum v3.61, allowing an attacker to read sensitive files (e.g., admin hash) and execute arbitrary PHP code by manipulating the registration process to create a malicious file.
Description
TinyPHPForum 3.6 - 'UpdatePF.php' Authentication Bypass
Exploits (1)
This exploit demonstrates an authentication bypass and arbitrary file read vulnerability in TinyPHPForum v3.61, allowing an attacker to read sensitive files (e.g., admin hash) and execute arbitrary PHP code by manipulating the registration process to create a malicious file.