EIP-2026-114506
PRE-CVEYapBB 1.2 - 'cfgIncludeDirectory' Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114506. PoCs published by cijfer.
AI-analyzed exploit summary This Perl script exploits a remote command execution vulnerability in YapBB <=1.2 Beta by injecting malicious code via the `cfgIncludeDirectory` parameter in `global.php`. It uses LWP::UserAgent to send crafted HTTP requests and retrieves command output from a specified PHP shell.
Description
YapBB 1.2 - 'cfgIncludeDirectory' Remote Command Execution
Exploits (1)
This Perl script exploits a remote command execution vulnerability in YapBB <=1.2 Beta by injecting malicious code via the `cfgIncludeDirectory` parameter in `global.php`. It uses LWP::UserAgent to send crafted HTTP requests and retrieves command output from a specified PHP shell.