EIP-2026-109590
PRE-CVEMoreGroupWare 0.6.8 - WEBMAIL2_INC_DIR Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109590. PoCs published by phil dunn.
AI-analyzed exploit summary The vulnerability in moregroupware allows remote attackers to execute arbitrary PHP code by manipulating the include path via the 'webmail2_inc_dir' parameter. This is a remote file inclusion (RFI) vulnerability that can lead to remote code execution (RCE) under certain PHP configurations.
Description
MoreGroupWare 0.6.8 - WEBMAIL2_INC_DIR Remote File Inclusion
Exploits (1)
The vulnerability in moregroupware allows remote attackers to execute arbitrary PHP code by manipulating the include path via the 'webmail2_inc_dir' parameter. This is a remote file inclusion (RFI) vulnerability that can lead to remote code execution (RCE) under certain PHP configurations.