EIP-2026-106069
PRE-CVEComdev eCommerce 3.0 - 'config.php' Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106069. PoCs published by anonymous.
AI-analyzed exploit summary The exploit demonstrates a remote file inclusion vulnerability in Comdev eCommerce by manipulating the 'path[docroot]' parameter to include and execute arbitrary server-side script code. The vulnerability arises from insufficient input sanitization, allowing an attacker to specify a remote URL containing malicious code.
Description
Comdev eCommerce 3.0 - 'config.php' Remote File Inclusion
Exploits (1)
The exploit demonstrates a remote file inclusion vulnerability in Comdev eCommerce by manipulating the 'path[docroot]' parameter to include and execute arbitrary server-side script code. The vulnerability arises from insufficient input sanitization, allowing an attacker to specify a remote URL containing malicious code.