EIP-2026-111433
PRE-CVEPostNuke 0.75/0.76 Blocks Module - Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111433. PoCs published by pokley.
AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in the PostNuke Blocks module, allowing attackers to disclose arbitrary files by manipulating the 'func' parameter with traversal sequences. The example URL demonstrates accessing '/etc/passwd' via a NULL byte-terminated path.
Description
PostNuke 0.75/0.76 Blocks Module - Directory Traversal
Exploits (1)
The exploit describes a directory traversal vulnerability in the PostNuke Blocks module, allowing attackers to disclose arbitrary files by manipulating the 'func' parameter with traversal sequences. The example URL demonstrates accessing '/etc/passwd' via a NULL byte-terminated path.