EIP-2026-110381

PRE-CVE

osCommerce 3.0a5 - Local File Inclusion / HTML Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110381. PoCs published by Jordi Chancel.

AI-analyzed exploit summary This is a vulnerability writeup describing a local file inclusion (LFI) and HTML injection vulnerability in osCommerce 3.0a5. It includes a proof-of-concept URL demonstrating directory traversal but lacks executable exploit code.

Description

osCommerce 3.0a5 - Local File Inclusion / HTML Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by Jordi Chancel · htmlwebappsphp
https://www.exploit-db.com/exploits/33913

This is a vulnerability writeup describing a local file inclusion (LFI) and HTML injection vulnerability in osCommerce 3.0a5. It includes a proof-of-concept URL demonstrating directory traversal but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: osCommerce 3.0a5
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026