EIP-2026-107519
PRE-CVEGuestbook Script 1.7 - 'include_files' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107519. PoCs published by rgod.
AI-analyzed exploit summary This Perl script exploits a file inclusion vulnerability in Guestbook Script <= 1.7 by either injecting PHP code into log files or including remote code via FTP. It demonstrates remote code execution (RCE) by leveraging the application's insecure handling of the `include_files` parameter.
Description
Guestbook Script 1.7 - 'include_files' Remote Code Execution
Exploits (1)
This Perl script exploits a file inclusion vulnerability in Guestbook Script <= 1.7 by either injecting PHP code into log files or including remote code via FTP. It demonstrates remote code execution (RCE) by leveraging the application's insecure handling of the `include_files` parameter.