EIP-2026-106457
PRE-CVEDirectAdmin 1.34.4 - Multiple Cross-Site Request Forgerys
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106457. PoCs published by K053.
AI-analyzed exploit summary This exploit demonstrates multiple CSRF vulnerabilities in DirectAdmin 1.34.4, allowing unauthorized actions such as adding/deleting subdomains, emails, and databases via crafted HTML forms or image tags. The PoC includes clear examples of malicious requests that can be triggered without user interaction.
Description
DirectAdmin 1.34.4 - Multiple Cross-Site Request Forgerys
Exploits (1)
This exploit demonstrates multiple CSRF vulnerabilities in DirectAdmin 1.34.4, allowing unauthorized actions such as adding/deleting subdomains, emails, and databases via crafted HTML forms or image tags. The PoC includes clear examples of malicious requests that can be triggered without user interaction.