Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105450. PoCs published by frog.
AI-analyzed exploit summary The entry describes a remote file inclusion vulnerability in BES-CMS versions 0.4 rc3 and 0.5 rc3, where an attacker can include malicious files via the 'inc_path' parameter in multiple scripts. The vulnerability allows arbitrary code execution by manipulating the 'inc_path' parameter to reference an external URL.
Description
BES-CMS 0.4/0.5 - 'start.php' File Inclusion
Exploits (1)
The entry describes a remote file inclusion vulnerability in BES-CMS versions 0.4 rc3 and 0.5 rc3, where an attacker can include malicious files via the 'inc_path' parameter in multiple scripts. The vulnerability allows arbitrary code execution by manipulating the 'inc_path' parameter to reference an external URL.