EIP-2026-112913
PRE-CVEUploader by CeleronDude 5.3.0 - Arbitrary File Upload (1)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112913. PoCs published by Stink.
AI-analyzed exploit summary This exploit leverages a file upload vulnerability in Uploader by CeleronDude 5.3.0, allowing attackers to bypass file extension restrictions by renaming a malicious PHP file to have a .pjpeg extension, leading to remote code execution (RCE). The vulnerability is trivial to exploit and requires no authentication.
Description
Uploader by CeleronDude 5.3.0 - Arbitrary File Upload (1)
Exploits (1)
This exploit leverages a file upload vulnerability in Uploader by CeleronDude 5.3.0, allowing attackers to bypass file extension restrictions by renaming a malicious PHP file to have a .pjpeg extension, leading to remote code execution (RCE). The vulnerability is trivial to exploit and requires no authentication.