EIP-2026-106485
PRE-CVEDocebo 3.6.0.2 (stable) - Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106485. PoCs published by Zer0 Thunder.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo 3.6.0.2 by manipulating the 'modname' parameter in the URL to include arbitrary files, such as 'boot.ini', via directory traversal sequences. The PoC is tested on a specific environment (WampServer 2.0i) and provides a clear example of the vulnerability.
Description
Docebo 3.6.0.2 (stable) - Local File Inclusion
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo 3.6.0.2 by manipulating the 'modname' parameter in the URL to include arbitrary files, such as 'boot.ini', via directory traversal sequences. The PoC is tested on a specific environment (WampServer 2.0i) and provides a clear example of the vulnerability.