Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-106073. PoCs published by B127Y.
AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in Cometchat: a code execution flaw via `call_user_func` in `chatrooms.php` and an XSS vulnerability in `handwrite/index.php`. Both are confirmed with live demo URLs.
Description
Cometchat - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by B127Y · textwebappsphp
https://www.exploit-db.com/exploits/24506
This exploit demonstrates two vulnerabilities in Cometchat: a code execution flaw via `call_user_func` in `chatrooms.php` and an XSS vulnerability in `handwrite/index.php`. Both are confirmed with live demo URLs.
Classification
Working Poc 90%
Attack Type
Rce | Xss
Complexity
Trivial
Reliability
Reliable
Target:
Cometchat (all versions)
No auth needed
Prerequisites:
Network access to the target Cometchat installation
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026