EIP-2026-107573
PRE-CVEHeffnerCMS 1.22 - 'index.php' Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107573. PoCs published by MiND C0re.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion vulnerability in HeffnerCMS 1.22 due to improper input sanitization. By appending a null byte (%00) to the 'page' parameter, an attacker can include arbitrary local files, potentially leading to sensitive information disclosure or remote code execution.
Description
HeffnerCMS 1.22 - 'index.php' Local File Inclusion
Exploits (1)
The exploit demonstrates a local file inclusion vulnerability in HeffnerCMS 1.22 due to improper input sanitization. By appending a null byte (%00) to the 'page' parameter, an attacker can include arbitrary local files, potentially leading to sensitive information disclosure or remote code execution.