Hundred Plus EIP Plus Arbitrary File Upload Vulnerability Allowing Remote Code Execution
Vulnerability
A vulnerability allowing arbitrary file upload has been identified in EIP Plus developed by Hundred Plus, affecting versions prior to RELEASE_240626. This vulnerability enables privileged remote attackers to upload and execute web shell backdoors, facilitating arbitrary code execution on the server.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the server where EIP Plus is installed.
Remediation
Users are advised to update to EIP Plus version RELEASE_240626 or later.
Added: Nov 10, 2025, 4:20 AM
Updated: Nov 10, 2025, 4:20 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
4.8remediation
7.7relevance
1.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
