EIP-2026-106230

PRE-CVE

Crafty Syntax Live Help 2.9.9 - Multiple Remote File Inclusions

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106230. PoCs published by Crackers_Child.

AI-analyzed exploit summary The provided text describes multiple remote file-include vulnerabilities in Crafty Syntax Live Help due to insufficient sanitization of user-supplied data. Exploiting these vulnerabilities could allow an attacker to compromise the application and underlying system.

Description

Crafty Syntax Live Help 2.9.9 - Multiple Remote File Inclusions

Exploits (1)

exploitdb WRITEUP VERIFIED
by Crackers_Child · textwebappsphp
https://www.exploit-db.com/exploits/28851

The provided text describes multiple remote file-include vulnerabilities in Crafty Syntax Live Help due to insufficient sanitization of user-supplied data. Exploiting these vulnerabilities could allow an attacker to compromise the application and underlying system.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Crafty Syntax Live Help 2.9.9 (with Text Based Database Support package)
No auth needed
Prerequisites: Target must be running Crafty Syntax Live Help 2.9.9 with Text Based Database Support package · Remote file inclusion must be enabled or allowed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026