EIP-2026-103344
PRE-CVEZeroShell 'cgi-bin/kerbynet' - Local File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103344. PoCs published by Yann CAM.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in a web management interface, including local file disclosure, session token generation bypass, and remote command execution leading to a reverse shell. The PoC leverages unauthenticated access to sensitive files and command injection via a DNS lookup form.
Description
ZeroShell 'cgi-bin/kerbynet' - Local File Disclosure
Exploits (1)
This exploit demonstrates multiple vulnerabilities in a web management interface, including local file disclosure, session token generation bypass, and remote command execution leading to a reverse shell. The PoC leverages unauthenticated access to sensitive files and command injection via a DNS lookup form.