EIP-2026-109983
PRE-CVENuke BookMarks 0.6 - 'Marks.php' Full Path Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109983. PoCs published by Gerardo Astharot Di Giacomo.
AI-analyzed exploit summary The provided code describes a path disclosure vulnerability in Nuke Bookmarks, where submitting invalid data via specific URLs may expose sensitive information. It includes example URLs demonstrating the issue but lacks executable exploit code.
Description
Nuke BookMarks 0.6 - 'Marks.php' Full Path Disclosure
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Gerardo Astharot Di Giacomo · textwebappsphp
https://www.exploit-db.com/exploits/25282
The provided code describes a path disclosure vulnerability in Nuke Bookmarks, where submitting invalid data via specific URLs may expose sensitive information. It includes example URLs demonstrating the issue but lacks executable exploit code.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
Nuke Bookmarks (version unspecified)
No auth needed
Prerequisites:
Access to the target web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026