EIP-2026-111893

PRE-CVE

SAPID CMS 1.2.3_rc3 - 'rootpath' Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111893. PoCs published by simo64.

AI-analyzed exploit summary This exploit targets SAPID CMS 123 rc3 by leveraging a remote file inclusion vulnerability in `get_infochannel.inc.php` and `get_tree.inc.php` due to unsanitized `$root_path` and `$GLOBALS["root_path"]` variables. It allows remote command execution by including a malicious file from an attacker-controlled server.

Description

SAPID CMS 1.2.3_rc3 - 'rootpath' Remote Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by simo64 · perlwebappsphp
https://www.exploit-db.com/exploits/2161

This exploit targets SAPID CMS 123 rc3 by leveraging a remote file inclusion vulnerability in `get_infochannel.inc.php` and `get_tree.inc.php` due to unsanitized `$root_path` and `$GLOBALS["root_path"]` variables. It allows remote command execution by including a malicious file from an attacker-controlled server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SAPID CMS 123 rc3
No auth needed
Prerequisites: Network access to the target SAPID CMS instance · Ability to host a malicious file on an attacker-controlled server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026