EIP-2026-106561
PRE-CVEDownload Management 1.00 for PHP-Fusion - Multiple Local File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106561. PoCs published by Psiczn.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Download Management for PHP-Fusion by manipulating the 'settings[locale]' parameter with a null byte (%00) to bypass input sanitization. This allows arbitrary local file access and potential execution of local scripts.
Description
Download Management 1.00 for PHP-Fusion - Multiple Local File Inclusions
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in Download Management for PHP-Fusion by manipulating the 'settings[locale]' parameter with a null byte (%00) to bypass input sanitization. This allows arbitrary local file access and potential execution of local scripts.