Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111287. PoCs published by Alfons Luja.
AI-analyzed exploit summary The writeup details a remote file deletion vulnerability in Pivot 1.40.6 due to improper handling of the `refkey` parameter in `count.php`, allowing deletion of arbitrary files when `register_globals` is enabled. The analysis includes code snippets and a proof-of-concept URL demonstrating the exploit.
Description
Pivot 1.40.6 - Arbitrary File Deletion
Exploits (1)
The writeup details a remote file deletion vulnerability in Pivot 1.40.6 due to improper handling of the `refkey` parameter in `count.php`, allowing deletion of arbitrary files when `register_globals` is enabled. The analysis includes code snippets and a proof-of-concept URL demonstrating the exploit.