Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109387. PoCs published by KnocKout inj3ct0r.
AI-analyzed exploit summary This exploit targets a file disclosure vulnerability in MediaSuite CMS by manipulating the 'force-download.php' script to read arbitrary files, specifically 'site-settings.php', which contains database credentials. The exploit constructs a malicious URL to bypass directory restrictions and download sensitive files.
Description
MediaSuite CMS - Artibary File Disclosure
Exploits (1)
This exploit targets a file disclosure vulnerability in MediaSuite CMS by manipulating the 'force-download.php' script to read arbitrary files, specifically 'site-settings.php', which contains database credentials. The exploit constructs a malicious URL to bypass directory restrictions and download sensitive files.