EIP-2026-112174
PRE-CVESire 2.0 - '/lire.php' Remote File Inclusion / Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112174. PoCs published by simo64.
AI-analyzed exploit summary The exploit demonstrates a file inclusion vulnerability in 'lire.php' due to improper input validation of the 'rub' parameter, allowing remote file inclusion when 'register_globals' is enabled. It also includes a file upload vulnerability in 'upload.php' that permits unauthorized file uploads.
Description
Sire 2.0 - '/lire.php' Remote File Inclusion / Arbitrary File Upload
Exploits (1)
The exploit demonstrates a file inclusion vulnerability in 'lire.php' due to improper input validation of the 'rub' parameter, allowing remote file inclusion when 'register_globals' is enabled. It also includes a file upload vulnerability in 'upload.php' that permits unauthorized file uploads.