Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110414. PoCs published by cOndemned.
AI-analyzed exploit summary The exploit demonstrates multiple local file inclusion (LFI) vulnerabilities in OvBB v0.16a due to improper handling of the CFG[skin] parameter in various template files. The PoC shows how an attacker can traverse directories to read arbitrary files (e.g., /etc/passwd) by manipulating the parameter.
Description
OvBB 0.16a - Multiple Local File Inclusions
Exploits (1)
The exploit demonstrates multiple local file inclusion (LFI) vulnerabilities in OvBB v0.16a due to improper handling of the CFG[skin] parameter in various template files. The PoC shows how an attacker can traverse directories to read arbitrary files (e.g., /etc/passwd) by manipulating the parameter.