Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-114631. PoCs published by Tauco.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Zomato Clone Script, allowing an attacker to upload a malicious PHP file disguised as an image (e.g., info.php.jpg) and execute arbitrary code on the server. The PoC includes a crafted HTTP POST request with a multipart form-data payload that bypasses file extension checks.
Description
Zomato Clone Script - Arbitrary File Upload
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Zomato Clone Script, allowing an attacker to upload a malicious PHP file disguised as an image (e.g., info.php.jpg) and execute arbitrary code on the server. The PoC includes a crafted HTTP POST request with a multipart form-data payload that bypasses file extension checks.