EIP-2026-105752
PRE-CVECart Engine 3.0.0 - Database Backup Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105752. PoCs published by LiquidWorm.
AI-analyzed exploit summary This PHP script exploits a predictable database backup filename vulnerability in Cart Engine 3.0.0, allowing unauthorized disclosure of sensitive database backups stored in the '/admin/backup' directory. It brute-forces possible filenames and checks for their existence via HTTP requests.
Description
Cart Engine 3.0.0 - Database Backup Disclosure
Exploits (1)
This PHP script exploits a predictable database backup filename vulnerability in Cart Engine 3.0.0, allowing unauthorized disclosure of sensitive database backups stored in the '/admin/backup' directory. It brute-forces possible filenames and checks for their existence via HTTP requests.