Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109490. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary This document describes a full path disclosure vulnerability in Miniweb 2.0, where an invalid module parameter triggers a PHP warning revealing the server's file path. The analysis includes technical details, sample exploit code, and a proposed fix.
Description
Miniweb 2.0 - Full Path Disclosure
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Salvatore Fresta · textwebappsphp
https://www.exploit-db.com/exploits/10395
This document describes a full path disclosure vulnerability in Miniweb 2.0, where an invalid module parameter triggers a PHP warning revealing the server's file path. The analysis includes technical details, sample exploit code, and a proposed fix.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Miniweb 2.0
No auth needed
Prerequisites:
Access to the target web application
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026