Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-101327. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This Python script exploits a directory traversal vulnerability in iPhone MyDocs 2.7 by sending crafted HTTP requests to access sensitive files on the device. It allows an attacker to retrieve files such as the address book, Safari data, and system files like /etc/passwd.
Description
iphone mydocs 2.7 - Directory Traversal
Exploits (1)
exploitdb
WORKING POC
by Khashayar Fereidani · pythonremotehardware
https://www.exploit-db.com/exploits/16245
This Python script exploits a directory traversal vulnerability in iPhone MyDocs 2.7 by sending crafted HTTP requests to access sensitive files on the device. It allows an attacker to retrieve files such as the address book, Safari data, and system files like /etc/passwd.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
iPhone MyDocs 2.7
No auth needed
Prerequisites:
Network access to the target device · MyDocs 2.7 running on the target iPhone
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026