EIP-2026-106968

PRE-CVE

Exponent CMS 2.0.0 Beta 1.1 - Local File Inclusion / Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106968. PoCs published by AutoSec Tools.

AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Exponent CMS by manipulating the 'controller' parameter to traverse directories and access sensitive files like 'win.ini'. It also mentions an arbitrary file upload vulnerability, though the provided code only shows the LFI vector.

Description

Exponent CMS 2.0.0 Beta 1.1 - Local File Inclusion / Arbitrary File Upload

Exploits (1)

exploitdb WORKING POC VERIFIED
by AutoSec Tools · textwebappsphp
https://www.exploit-db.com/exploits/35717

The exploit demonstrates a local file inclusion (LFI) vulnerability in Exponent CMS by manipulating the 'controller' parameter to traverse directories and access sensitive files like 'win.ini'. It also mentions an arbitrary file upload vulnerability, though the provided code only shows the LFI vector.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Exponent CMS 2.0.0 beta 1.1
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026