Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111894. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates a file inclusion vulnerability in SAPID-SHOP 1.3, where the `root_path` parameter in `get_tree.inc.php` is used to include arbitrary remote files, leading to potential remote code execution (RCE). The PoC shows how an attacker can include a malicious file hosted on a remote server.
Description
SAPID SHOP 1.3 - Remote File Inclusion
Exploits (1)
This exploit demonstrates a file inclusion vulnerability in SAPID-SHOP 1.3, where the `root_path` parameter in `get_tree.inc.php` is used to include arbitrary remote files, leading to potential remote code execution (RCE). The PoC shows how an attacker can include a malicious file hosted on a remote server.