EIP-2026-106783
PRE-CVEeFront 3.6.10 - 'download' Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106783. PoCs published by Chokri B.A.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in eFront 3.6.10, where insufficient input sanitization allows attackers to access sensitive files via a crafted URL parameter. The exploit leverages the 'download' parameter in the 'student.php' endpoint to traverse directories and retrieve arbitrary files.
Description
eFront 3.6.10 - 'download' Directory Traversal
Exploits (1)
The provided text describes a directory traversal vulnerability in eFront 3.6.10, where insufficient input sanitization allows attackers to access sensitive files via a crafted URL parameter. The exploit leverages the 'download' parameter in the 'student.php' endpoint to traverse directories and retrieve arbitrary files.