EIP-2026-113304

PRE-CVE

Webify Blog - Arbitrary File Deletion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113304. PoCs published by JIKO.

AI-analyzed exploit summary The exploit demonstrates an arbitrary file deletion vulnerability in Webify Blog by manipulating the post ID in the URL. It allows attackers to delete files uploaded in posts, potentially enabling further exploitation if PHP uploads are allowed.

Description

Webify Blog - Arbitrary File Deletion

Exploits (1)

exploitdb WORKING POC VERIFIED
by JIKO · textwebappsphp
https://www.exploit-db.com/exploits/21250

The exploit demonstrates an arbitrary file deletion vulnerability in Webify Blog by manipulating the post ID in the URL. It allows attackers to delete files uploaded in posts, potentially enabling further exploitation if PHP uploads are allowed.

Classification
Working Poc 80%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Webify Blog
No auth needed
Prerequisites: Access to the target server's blog uploads directory
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026