EIP-2026-111893
PRE-CVESAPID CMS 1.2.3_rc3 - 'rootpath' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111893. PoCs published by simo64.
AI-analyzed exploit summary This exploit targets SAPID CMS 123 rc3 by leveraging a remote file inclusion vulnerability in `get_infochannel.inc.php` and `get_tree.inc.php` due to unsanitized `$root_path` and `$GLOBALS["root_path"]` variables. It allows remote command execution by including a malicious file from an attacker-controlled server.
Description
SAPID CMS 1.2.3_rc3 - 'rootpath' Remote Code Execution
Exploits (1)
This exploit targets SAPID CMS 123 rc3 by leveraging a remote file inclusion vulnerability in `get_infochannel.inc.php` and `get_tree.inc.php` due to unsanitized `$root_path` and `$GLOBALS["root_path"]` variables. It allows remote command execution by including a malicious file from an attacker-controlled server.