EIP-2026-110281
PRE-CVEOpenDb 1.5.0.4 - Multiple Local File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110281. PoCs published by ViRuSMaN.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in OpenDb 1.5.0.4 due to improper input validation in the `_OPENDB_THEME` and `site_plugin_classname` parameters. The vulnerability allows an attacker to include arbitrary local files by appending a null byte (`%00`) to bypass file extension checks.
Description
OpenDb 1.5.0.4 - Multiple Local File Inclusions
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in OpenDb 1.5.0.4 due to improper input validation in the `_OPENDB_THEME` and `site_plugin_classname` parameters. The vulnerability allows an attacker to include arbitrary local files by appending a null byte (`%00`) to bypass file extension checks.