EIP-2026-111194

PRE-CVE

phpScribe 0.9 - 'user.cfg' Remote Configuration Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111194. PoCs published by ahmadbady.

AI-analyzed exploit summary This entry describes a remote configuration file disclosure vulnerability in phpscribe-0.9, where sensitive database credentials are exposed via direct access to the user.cfg file. The advisory includes the vulnerable file path and sample configuration content.

Description

phpScribe 0.9 - 'user.cfg' Remote Configuration Disclosure

Exploits (1)

exploitdb WRITEUP VERIFIED
by ahmadbady · textwebappsphp
https://www.exploit-db.com/exploits/7639

This entry describes a remote configuration file disclosure vulnerability in phpscribe-0.9, where sensitive database credentials are exposed via direct access to the user.cfg file. The advisory includes the vulnerable file path and sample configuration content.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: phpscribe-0.9
No auth needed
Prerequisites: Access to the target web server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026