EIP-2026-109983

PRE-CVE

Nuke BookMarks 0.6 - 'Marks.php' Full Path Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109983. PoCs published by Gerardo Astharot Di Giacomo.

AI-analyzed exploit summary The provided code describes a path disclosure vulnerability in Nuke Bookmarks, where submitting invalid data via specific URLs may expose sensitive information. It includes example URLs demonstrating the issue but lacks executable exploit code.

Description

Nuke BookMarks 0.6 - 'Marks.php' Full Path Disclosure

Exploits (1)

exploitdb WRITEUP VERIFIED
by Gerardo Astharot Di Giacomo · textwebappsphp
https://www.exploit-db.com/exploits/25282

The provided code describes a path disclosure vulnerability in Nuke Bookmarks, where submitting invalid data via specific URLs may expose sensitive information. It includes example URLs demonstrating the issue but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Nuke Bookmarks (version unspecified)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026