EIP-2026-106230
PRE-CVECrafty Syntax Live Help 2.9.9 - Multiple Remote File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106230. PoCs published by Crackers_Child.
AI-analyzed exploit summary The provided text describes multiple remote file-include vulnerabilities in Crafty Syntax Live Help due to insufficient sanitization of user-supplied data. Exploiting these vulnerabilities could allow an attacker to compromise the application and underlying system.
Description
Crafty Syntax Live Help 2.9.9 - Multiple Remote File Inclusions
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Crackers_Child · textwebappsphp
https://www.exploit-db.com/exploits/28851
The provided text describes multiple remote file-include vulnerabilities in Crafty Syntax Live Help due to insufficient sanitization of user-supplied data. Exploiting these vulnerabilities could allow an attacker to compromise the application and underlying system.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:
Crafty Syntax Live Help 2.9.9 (with Text Based Database Support package)
No auth needed
Prerequisites:
Target must be running Crafty Syntax Live Help 2.9.9 with Text Based Database Support package · Remote file inclusion must be enabled or allowed
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026