EIP-2026-111617
PRE-CVEqEngine 4.1.6/6.0.0 - 'task.php' Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111617. PoCs published by Gjoko Krstic.
AI-analyzed exploit summary The code describes a local file inclusion (LFI) vulnerability in qEngine due to improper input sanitization, allowing directory traversal attacks to access sensitive files like 'win.ini'. The exploit leverages a crafted URL to traverse directories and include arbitrary files.
Description
qEngine 4.1.6/6.0.0 - 'task.php' Local File Inclusion
Exploits (1)
The code describes a local file inclusion (LFI) vulnerability in qEngine due to improper input sanitization, allowing directory traversal attacks to access sensitive files like 'win.ini'. The exploit leverages a crafted URL to traverse directories and include arbitrary files.