EIP-2026-105448
PRE-CVEBES-CMS 0.4/0.5 - 'index.inc.php' File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105448. PoCs published by frog.
AI-analyzed exploit summary The entry describes a remote file inclusion vulnerability in BES-CMS versions 0.4 rc3 and 0.5 rc3, where an attacker can include malicious files via the 'PATH_Includes' parameter in multiple scripts. The provided URL demonstrates the exploit vector but lacks functional exploit code.
Description
BES-CMS 0.4/0.5 - 'index.inc.php' File Inclusion
Exploits (1)
The entry describes a remote file inclusion vulnerability in BES-CMS versions 0.4 rc3 and 0.5 rc3, where an attacker can include malicious files via the 'PATH_Includes' parameter in multiple scripts. The provided URL demonstrates the exploit vector but lacks functional exploit code.