EIP-2026-106673
PRE-CVEe107 Image Gallery Plugin - 'name' Remote File Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106673. PoCs published by Sammy FORGIT.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in the Image Gallery Plugin for e107, allowing an attacker to read arbitrary local files by manipulating the 'name' parameter in the URL. The provided example shows how to access the 'e107_config.php' file, which may contain sensitive configuration details.
Description
e107 Image Gallery Plugin - 'name' Remote File Disclosure
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in the Image Gallery Plugin for e107, allowing an attacker to read arbitrary local files by manipulating the 'name' parameter in the URL. The provided example shows how to access the 'e107_config.php' file, which may contain sensitive configuration details.