EIP-2026-114460
PRE-CVEXOOPS 2.3.2 - 'mydirname' PHP Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114460. PoCs published by StAkeR.
AI-analyzed exploit summary This PHP script exploits a remote code execution vulnerability in XOOPS 2.3.2 by injecting arbitrary PHP code via the 'mydirname' parameter in multiple scripts within the 'xoops_lib/modules/protector/' directory. It establishes an interactive shell for command execution on the target system.
Description
XOOPS 2.3.2 - 'mydirname' PHP Remote Code Execution
Exploits (1)
This PHP script exploits a remote code execution vulnerability in XOOPS 2.3.2 by injecting arbitrary PHP code via the 'mydirname' parameter in multiple scripts within the 'xoops_lib/modules/protector/' directory. It establishes an interactive shell for command execution on the target system.