EIP-2026-113020
PRE-CVEvBulletin ImpEx 1.74 - Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113020. PoCs published by ReZEN.
AI-analyzed exploit summary This PHP script exploits a remote file inclusion vulnerability in vBulletin's ImpEx module by injecting a malicious PHP file via the 'systempath' parameter. It allows remote command execution by writing a payload to a local file and then including it through the vulnerable endpoint.
Description
vBulletin ImpEx 1.74 - Remote Command Execution
Exploits (1)
This PHP script exploits a remote file inclusion vulnerability in vBulletin's ImpEx module by injecting a malicious PHP file via the 'systempath' parameter. It allows remote command execution by writing a payload to a local file and then including it through the vulnerable endpoint.