EIP-2026-106056
PRE-CVECollaborative Passwords Manager 1.07 - Multiple Local File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106056. PoCs published by sh00t0ut.
AI-analyzed exploit summary This exploit demonstrates a local file inclusion (LFI) vulnerability in Collaborative Passwords Manager 1.07 by manipulating the `_SESSION[user_language]` parameter to include arbitrary files (e.g., `/etc/passwd`). The null byte (`%00`) is used to terminate the file path, bypassing any appended extensions.
Description
Collaborative Passwords Manager 1.07 - Multiple Local File Inclusions
Exploits (1)
This exploit demonstrates a local file inclusion (LFI) vulnerability in Collaborative Passwords Manager 1.07 by manipulating the `_SESSION[user_language]` parameter to include arbitrary files (e.g., `/etc/passwd`). The null byte (`%00`) is used to terminate the file path, bypassing any appended extensions.