EIP-2026-105564
PRE-CVEBlursoft Blur6ex 0.3.462 - 'index.php' Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105564. PoCs published by Hamid Ebadi.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Blur6ex 0.3.462 by manipulating the 'shard' parameter in the URL to traverse directories and include arbitrary local files. The null byte (%00) is used to terminate the file path, bypassing any appended extensions or restrictions.
Description
Blursoft Blur6ex 0.3.462 - 'index.php' Local File Inclusion
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in Blur6ex 0.3.462 by manipulating the 'shard' parameter in the URL to traverse directories and include arbitrary local files. The null byte (%00) is used to terminate the file path, bypassing any appended extensions or restrictions.