EIP-2026-109817
PRE-CVEN/X Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109817. PoCs published by eidelweiss.
AI-analyzed exploit summary The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in N/X WCMS 4.5 due to insecure handling of user-supplied input in various PHP scripts. Attackers can inject malicious shell paths via parameters like 'path' and 'c[path]' to achieve remote code execution.
Description
N/X Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates multiple remote file inclusion (RFI) vulnerabilities in N/X WCMS 4.5 due to insecure handling of user-supplied input in various PHP scripts. Attackers can inject malicious shell paths via parameters like 'path' and 'c[path]' to achieve remote code execution.