EIP-2026-100507
PRE-CVEQuadComm Q-Shop 2.5 - Failure To Validate Credentials
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100507. PoCs published by G00db0y.
AI-analyzed exploit summary This ASP script exploits an authentication bypass in Q-Shop ASP shopping cart software to read sensitive files (admin credentials and database configuration) by directly accessing the file upload interface without authentication. It uses ActiveXObject to perform server-side file reading and dumps the contents to the web.
Description
QuadComm Q-Shop 2.5 - Failure To Validate Credentials
Exploits (1)
This ASP script exploits an authentication bypass in Q-Shop ASP shopping cart software to read sensitive files (admin credentials and database configuration) by directly accessing the file upload interface without authentication. It uses ActiveXObject to perform server-side file reading and dumps the contents to the web.