EIP-2026-103229
PRE-CVETalentSoft Web+ Application Server (Linux) 4.6 - Example Script File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103229. PoCs published by DCIST.
AI-analyzed exploit summary The exploit demonstrates a command injection vulnerability in Web+ on Linux systems via the Web+Ping script, which fails to filter shell metacharacters. An attacker can append commands (e.g., '| cat /etc/passwd') to the host parameter to achieve remote code execution.
Description
TalentSoft Web+ Application Server (Linux) 4.6 - Example Script File Disclosure
Exploits (1)
The exploit demonstrates a command injection vulnerability in Web+ on Linux systems via the Web+Ping script, which fails to filter shell metacharacters. An attacker can append commands (e.g., '| cat /etc/passwd') to the host parameter to achieve remote code execution.