EIP-2026-107519

PRE-CVE

Guestbook Script 1.7 - 'include_files' Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107519. PoCs published by rgod.

AI-analyzed exploit summary This Perl script exploits a file inclusion vulnerability in Guestbook Script <= 1.7 by either injecting PHP code into log files or including remote code via FTP. It demonstrates remote code execution (RCE) by leveraging the application's insecure handling of the `include_files` parameter.

Description

Guestbook Script 1.7 - 'include_files' Remote Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · perlwebappsphp
https://www.exploit-db.com/exploits/1575

This Perl script exploits a file inclusion vulnerability in Guestbook Script <= 1.7 by either injecting PHP code into log files or including remote code via FTP. It demonstrates remote code execution (RCE) by leveraging the application's insecure handling of the `include_files` parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Guestbook Script <= 1.7
No auth needed
Prerequisites: PHP5 with allow_url_fopen enabled (for FTP inclusion) · Access to log files (for log poisoning)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026