Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109853. PoCs published by cr4wl3r.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in Nensor CMS 2.01: a Local File Inclusion (LFI) via the 'sPage' parameter and an authentication bypass using SQL injection. The LFI allows arbitrary file inclusion by appending a null byte, while the SQL injection bypasses authentication with a simple ' or '1=1' payload.
Description
nensor CMS 2.01 - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates two vulnerabilities in Nensor CMS 2.01: a Local File Inclusion (LFI) via the 'sPage' parameter and an authentication bypass using SQL injection. The LFI allows arbitrary file inclusion by appending a null byte, while the SQL injection bypasses authentication with a simple ' or '1=1' payload.