EIP-2026-105487
PRE-CVEBitbot (C2 Web Panel) - 'gate2.php' Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105487. PoCs published by bwall.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Bitbot C2 Panel's gate2.php. It includes PoCs for command injection (drop), DoS via SQLi (dos), and persistent XSS (xss).
Description
Bitbot (C2 Web Panel) - 'gate2.php' Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
by bwall · pythonwebappsphp
https://www.exploit-db.com/exploits/27750
This exploit demonstrates SQL injection and XSS vulnerabilities in Bitbot C2 Panel's gate2.php. It includes PoCs for command injection (drop), DoS via SQLi (dos), and persistent XSS (xss).
Classification
Working Poc 95%
Attack Type
Sqli | Xss | Dos
Complexity
Moderate
Reliability
Reliable
Target:
Bitbot C2 Panel (version unspecified)
No auth needed
Prerequisites:
Network access to the Bitbot C2 Panel · gate2.php endpoint exposed
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026