Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109975. PoCs published by Ahlspiess.
AI-analyzed exploit summary The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in nuBuilder's report.php due to insecure handling of the $GLOBALS['StartingDirectory'] variable. It shows how an attacker can include a remote shell by manipulating the StartingDirectory parameter, bypassing register_globals settings.
Description
nuBuilder - Remote File Inclusion
Exploits (1)
The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in nuBuilder's report.php due to insecure handling of the $GLOBALS['StartingDirectory'] variable. It shows how an attacker can include a remote shell by manipulating the StartingDirectory parameter, bypassing register_globals settings.