EIP-2026-105009
PRE-CVEAFCommerce - 'controlheader.php' Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105009. PoCs published by NoGe.
AI-analyzed exploit summary The provided text describes a remote file inclusion (RFI) vulnerability in AFCommerce, where insufficient input sanitization in the 'rootpathtocart' parameter allows arbitrary file inclusion. The example URL demonstrates the vulnerability but does not include functional exploit code.
Description
AFCommerce - 'controlheader.php' Remote File Inclusion
Exploits (1)
The provided text describes a remote file inclusion (RFI) vulnerability in AFCommerce, where insufficient input sanitization in the 'rootpathtocart' parameter allows arbitrary file inclusion. The example URL demonstrates the vulnerability but does not include functional exploit code.