EIP-2026-103308
PRE-CVEPaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103308. PoCs published by ParagonSec.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in PaloAlto Networks Expedition Migration Tool 1.0.106 by leveraging a path traversal flaw in the API endpoint `/API/process/checkPidStatus.php`. The script sends a crafted POST request with a manipulated `pid` parameter to read arbitrary files on the server.
Description
PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in PaloAlto Networks Expedition Migration Tool 1.0.106 by leveraging a path traversal flaw in the API endpoint `/API/process/checkPidStatus.php`. The script sends a crafted POST request with a manipulated `pid` parameter to read arbitrary files on the server.