EIP-2026-103814
PRE-CVESmartFoxServer 2X 2.17.0 - Credentials Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103814. PoCs published by LiquidWorm.
AI-analyzed exploit summary The vulnerability involves SmartFoxServer 2X storing sensitive credentials in an unencrypted XML file (/config/server.xml), allowing local attackers with session access to disclose plain-text credentials. The writeup includes technical details such as file paths, affected versions, and proof of credential exposure via command-line examples.
Description
SmartFoxServer 2X 2.17.0 - Credentials Disclosure
Exploits (1)
The vulnerability involves SmartFoxServer 2X storing sensitive credentials in an unencrypted XML file (/config/server.xml), allowing local attackers with session access to disclose plain-text credentials. The writeup includes technical details such as file paths, affected versions, and proof of credential exposure via command-line examples.