EIP-2026-114470
PRE-CVEXOOPS Cube PROJECT FileManager - 'xupload.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114470. PoCs published by KedAns-Dz.
AI-analyzed exploit summary This PHP script exploits an arbitrary file upload vulnerability in FileManager by sending a POST request to 'xupload.php' with a user-supplied file path. The lack of input sanitization allows an attacker to upload malicious files, potentially leading to remote code execution.
Description
XOOPS Cube PROJECT FileManager - 'xupload.php' Arbitrary File Upload
Exploits (1)
This PHP script exploits an arbitrary file upload vulnerability in FileManager by sending a POST request to 'xupload.php' with a user-supplied file path. The lack of input sanitization allows an attacker to upload malicious files, potentially leading to remote code execution.