Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110615. PoCs published by cOndemned.
AI-analyzed exploit summary The exploit demonstrates a Local File Inclusion (LFI) vulnerability in PhotoDiary 1.3 due to improper handling of the 'lng' parameter in /admin/install.php. The PoC shows how an attacker can traverse directories to read arbitrary files, such as /etc/passwd, by injecting path traversal sequences.
Description
PhotoDiary 1.3 - 'lng' Local File Inclusion
Exploits (1)
The exploit demonstrates a Local File Inclusion (LFI) vulnerability in PhotoDiary 1.3 due to improper handling of the 'lng' parameter in /admin/install.php. The PoC shows how an attacker can traverse directories to read arbitrary files, such as /etc/passwd, by injecting path traversal sequences.