EIP-2026-111693
PRE-CVErConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111693. PoCs published by Murat ŞEKER.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in rConfig 3.9.6 via the 'path' parameter in /lib/ajaxHandlers/ajaxGetFileByPath.php. Authenticated users can read arbitrary files on the server by traversing directories (e.g., ../../../../../../etc/passwd).
Description
rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in rConfig 3.9.6 via the 'path' parameter in /lib/ajaxHandlers/ajaxGetFileByPath.php. Authenticated users can read arbitrary files on the server by traversing directories (e.g., ../../../../../../etc/passwd).