EIP-2026-104261
PRE-CVEGeoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104261. PoCs published by David Bloom.
AI-analyzed exploit summary This Python script exploits an XXE vulnerability in GeoServer versions <2.7.1.1, <2.6.4, and <2.5.5.1 by crafting a malicious XML payload to read arbitrary files or list directories on the server. It automates the discovery of GeoServer features and constructs the exploit URL dynamically.
Description
Geoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
Exploits (1)
This Python script exploits an XXE vulnerability in GeoServer versions <2.7.1.1, <2.6.4, and <2.5.5.1 by crafting a malicious XML payload to read arbitrary files or list directories on the server. It automates the discovery of GeoServer features and constructs the exploit URL dynamically.