EIP-2026-113791
PRE-CVEWordPress Plugin Global Flash Gallery - 'swfupload.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113791. PoCs published by Ashiyane Digital Security Team.
AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in the Global Flash Gallery WordPress plugin by bypassing file extension validation. It sends a POST request with a malicious file disguised as an image (file.php.gif) to swfupload.php, potentially leading to remote code execution.
Description
WordPress Plugin Global Flash Gallery - 'swfupload.php' Arbitrary File Upload
Exploits (1)
This Perl script exploits an arbitrary file upload vulnerability in the Global Flash Gallery WordPress plugin by bypassing file extension validation. It sends a POST request with a malicious file disguised as an image (file.php.gif) to swfupload.php, potentially leading to remote code execution.