EIP-2026-105487

PRE-CVE

Bitbot (C2 Web Panel) - 'gate2.php' Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105487. PoCs published by bwall.

AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Bitbot C2 Panel's gate2.php. It includes PoCs for command injection (drop), DoS via SQLi (dos), and persistent XSS (xss).

Description

Bitbot (C2 Web Panel) - 'gate2.php' Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by bwall · pythonwebappsphp
https://www.exploit-db.com/exploits/27750

This exploit demonstrates SQL injection and XSS vulnerabilities in Bitbot C2 Panel's gate2.php. It includes PoCs for command injection (drop), DoS via SQLi (dos), and persistent XSS (xss).

Classification
Working Poc 95%
Attack Type
Sqli | Xss | Dos
Complexity
Moderate
Reliability
Reliable
Target: Bitbot C2 Panel (version unspecified)
No auth needed
Prerequisites: Network access to the Bitbot C2 Panel · gate2.php endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026