EIP-2026-100649

PRE-CVE

DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100649. PoCs published by Glafkos Charalambous.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated arbitrary file download vulnerability in DotNetNuke DreamSlider module version 01.01.02 and below. It allows remote attackers to download arbitrary files from the server by manipulating the 'File' parameter in a GET request.

Description

DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download (Metasploit)

Exploits (1)

exploitdb WORKING POC
by Glafkos Charalambous · rubywebappsaspx
https://www.exploit-db.com/exploits/43405

This Metasploit module exploits an unauthenticated arbitrary file download vulnerability in DotNetNuke DreamSlider module version 01.01.02 and below. It allows remote attackers to download arbitrary files from the server by manipulating the 'File' parameter in a GET request.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: DotNetNuke DreamSlider Module <= 01.01.02
No auth needed
Prerequisites: Target must have the vulnerable DreamSlider module installed · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026