Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109252. PoCs published by mr_me.
AI-analyzed exploit summary This exploit targets a local file download vulnerability in Maian Gallery v2 by manipulating the `mgallery_theme_cookie` parameter to traverse directories and download sensitive files like `/etc/passwd` and `/etc/mysql/my.cnf`. It uses a null byte (`%00`) to bypass file extension restrictions.
Description
Maian Gallery 2 - Local File Download
Exploits (1)
This exploit targets a local file download vulnerability in Maian Gallery v2 by manipulating the `mgallery_theme_cookie` parameter to traverse directories and download sensitive files like `/etc/passwd` and `/etc/mysql/my.cnf`. It uses a null byte (`%00`) to bypass file extension restrictions.