EIP-2026-100716
PRE-CVEExcite for Web Servers 1.1 - Administrative Password
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100716. PoCs published by Michael Gerdts.
AI-analyzed exploit summary This exploit leverages a world-writable configuration file in Excite for Web Servers 1.1 to bypass authentication by directly submitting an encrypted password to the AT-generate.cgi script. The attacker can either read the existing encrypted password or overwrite it with a custom one.
Description
Excite for Web Servers 1.1 - Administrative Password
Exploits (1)
This exploit leverages a world-writable configuration file in Excite for Web Servers 1.1 to bypass authentication by directly submitting an encrypted password to the AT-generate.cgi script. The attacker can either read the existing encrypted password or overwrite it with a custom one.