EIP-2026-105000

PRE-CVE

ae2 - 'standart.inc.php' Remote File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105000. PoCs published by k1tk4t.

AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the 'standart.inc.php' file of the ae2 software. The vulnerability arises from insecure usage of the 'topdir' parameter, allowing an attacker to include remote files and potentially execute arbitrary code.

Description

ae2 - 'standart.inc.php' Remote File Inclusion

Exploits (1)

exploitdb WORKING POC VERIFIED
by k1tk4t · textwebappsphp
https://www.exploit-db.com/exploits/2513

This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in the 'standart.inc.php' file of the ae2 software. The vulnerability arises from insecure usage of the 'topdir' parameter, allowing an attacker to include remote files and potentially execute arbitrary code.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ae2 (version not specified)
No auth needed
Prerequisites: Remote file inclusion must be enabled on the target server · Attacker must be able to reach the target URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026