Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-102434. PoCs published by Raki Ben Hamouda.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in WSO2 API Manager 3.1.0 via a path traversal attack in the `extensionName` parameter of the `/carbon/extensions/deleteExtension-ajaxprocessor.jsp` endpoint. The PoC shows how an authenticated attacker can delete system files by sending a crafted POST request.
Description
WSO2 3.1.0 - Arbitrary File Delete
Exploits (1)
This exploit demonstrates an arbitrary file deletion vulnerability in WSO2 API Manager 3.1.0 via a path traversal attack in the `extensionName` parameter of the `/carbon/extensions/deleteExtension-ajaxprocessor.jsp` endpoint. The PoC shows how an authenticated attacker can delete system files by sending a crafted POST request.