Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105291. PoCs published by Julian Horoszkiewicz.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion vulnerability in ATutor 2.1 by manipulating the 'tool_file' parameter to traverse directories and access sensitive files like '/etc/passwd'. The vulnerability arises from insufficient input sanitization in the 'index.php' script.
Description
ATutor 2.1 - 'tool_file' Local File Inclusion
Exploits (1)
The exploit demonstrates a local file inclusion vulnerability in ATutor 2.1 by manipulating the 'tool_file' parameter to traverse directories and access sensitive files like '/etc/passwd'. The vulnerability arises from insufficient input sanitization in the 'index.php' script.