EIP-2026-113193
PRE-CVEWBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113193. PoCs published by tmrswrr.
AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in WBCE CMS 1.6.1, allowing an authenticated admin to upload a malicious PHP file (upgrade.php) via the language installation feature, leading to remote command execution (RCE). The PoC includes a multipart form upload with a PHP payload executing the 'id' command.
Description
WBCE CMS Version 1.6.1 - Remote Command Execution (Authenticated)
Exploits (1)
This exploit demonstrates a file upload vulnerability in WBCE CMS 1.6.1, allowing an authenticated admin to upload a malicious PHP file (upgrade.php) via the language installation feature, leading to remote command execution (RCE). The PoC includes a multipart form upload with a PHP payload executing the 'id' command.