EIP-2026-110017
PRE-CVEOctogate UTM 3.0.12 - Admin Interface Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110017. PoCs published by Oliver Karow.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in Octogate UTM's web interface, specifically in the `/scripts/download.php` script, which allows unauthenticated access to files outside the web root. The example request demonstrates how to retrieve sensitive configuration files using a crafted HTTP GET request.
Description
Octogate UTM 3.0.12 - Admin Interface Directory Traversal
Exploits (1)
The exploit describes a directory traversal vulnerability in Octogate UTM's web interface, specifically in the `/scripts/download.php` script, which allows unauthenticated access to files outside the web root. The example request demonstrates how to retrieve sensitive configuration files using a crafted HTTP GET request.