EIP-2026-111287

PRE-CVE

Pivot 1.40.6 - Arbitrary File Deletion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111287. PoCs published by Alfons Luja.

AI-analyzed exploit summary The writeup details a remote file deletion vulnerability in Pivot 1.40.6 due to improper handling of the `refkey` parameter in `count.php`, allowing deletion of arbitrary files when `register_globals` is enabled. The analysis includes code snippets and a proof-of-concept URL demonstrating the exploit.

Description

Pivot 1.40.6 - Arbitrary File Deletion

Exploits (1)

exploitdb WRITEUP VERIFIED
by Alfons Luja · textwebappsphp
https://www.exploit-db.com/exploits/8239

The writeup details a remote file deletion vulnerability in Pivot 1.40.6 due to improper handling of the `refkey` parameter in `count.php`, allowing deletion of arbitrary files when `register_globals` is enabled. The analysis includes code snippets and a proof-of-concept URL demonstrating the exploit.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Pivot 1.40.6
No auth needed
Prerequisites: register_globals enabled · knowledge of target file paths
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026