Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109913. PoCs published by G00db0y.
AI-analyzed exploit summary The provided code describes a path disclosure vulnerability in News Wizard software. It triggers an error page by sending a malformed request to 'article.php' with an invalid 'id' parameter, potentially leaking system path information.
Description
News Wizard 2.0 - Full Path Disclosure
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by G00db0y · textwebappsphp
https://www.exploit-db.com/exploits/23012
The provided code describes a path disclosure vulnerability in News Wizard software. It triggers an error page by sending a malformed request to 'article.php' with an invalid 'id' parameter, potentially leaking system path information.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
News Wizard (version unspecified)
No auth needed
Prerequisites:
Access to the target web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026