Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105758. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in CAT2 <= 1.2 by manipulating the 'spaw_root' parameter to include arbitrary files (e.g., /etc/passwd) via a null byte injection. The attack leverages improper input validation in the 'spaw_control.class.php' script.
Description
CAT2 - 'spaw_root' Local File Inclusion
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in CAT2 <= 1.2 by manipulating the 'spaw_root' parameter to include arbitrary files (e.g., /etc/passwd) via a null byte injection. The attack leverages improper input validation in the 'spaw_control.class.php' script.