EIP-2026-106673

PRE-CVE

e107 Image Gallery Plugin - 'name' Remote File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106673. PoCs published by Sammy FORGIT.

AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in the Image Gallery Plugin for e107, allowing an attacker to read arbitrary local files by manipulating the 'name' parameter in the URL. The provided example shows how to access the 'e107_config.php' file, which may contain sensitive configuration details.

Description

e107 Image Gallery Plugin - 'name' Remote File Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sammy FORGIT · textwebappsphp
https://www.exploit-db.com/exploits/37432

The exploit demonstrates a directory traversal vulnerability in the Image Gallery Plugin for e107, allowing an attacker to read arbitrary local files by manipulating the 'name' parameter in the URL. The provided example shows how to access the 'e107_config.php' file, which may contain sensitive configuration details.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Image Gallery Plugin for e107 0.9.7.1
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026