Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111690. PoCs published by Gregory Pickett.
AI-analyzed exploit summary The writeup describes a local file inclusion vulnerability in rConfig's downloadFile.php, allowing authenticated users to download arbitrary files from the server. The vulnerability is due to lack of validation on the download_file parameter.
Description
rConfig 3.1.1 - Local File Inclusion
Exploits (1)
exploitdb
WRITEUP
by Gregory Pickett · textwebappsphp
https://www.exploit-db.com/exploits/39898
The writeup describes a local file inclusion vulnerability in rConfig's downloadFile.php, allowing authenticated users to download arbitrary files from the server. The vulnerability is due to lack of validation on the download_file parameter.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
rConfig 3.1.1 and earlier
Auth required
Prerequisites:
Authenticated access to the rConfig application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026