Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111764. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in NPDS REvolution 10.02, allowing an attacker to inject PHP code into the 'footer_after' configuration file via a crafted HTTP request. The PoC uses an img tag to trigger the malicious request, potentially leading to remote code execution if the victim is an authenticated admin.
Description
REvolution 10.02 - Cross-Site Request Forgery
Exploits (1)
This exploit demonstrates a CSRF vulnerability in NPDS REvolution 10.02, allowing an attacker to inject PHP code into the 'footer_after' configuration file via a crafted HTTP request. The PoC uses an img tag to trigger the malicious request, potentially leading to remote code execution if the victim is an authenticated admin.