EIP-2026-106968
PRE-CVEExponent CMS 2.0.0 Beta 1.1 - Local File Inclusion / Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106968. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Exponent CMS by manipulating the 'controller' parameter to traverse directories and access sensitive files like 'win.ini'. It also mentions an arbitrary file upload vulnerability, though the provided code only shows the LFI vector.
Description
Exponent CMS 2.0.0 Beta 1.1 - Local File Inclusion / Arbitrary File Upload
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in Exponent CMS by manipulating the 'controller' parameter to traverse directories and access sensitive files like 'win.ini'. It also mentions an arbitrary file upload vulnerability, though the provided code only shows the LFI vector.