EIP-2026-112519
PRE-CVESyCtel Design - 'menu' Multiple Local File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112519. PoCs published by Ashiyane Digital Security Team.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in SyCtel Design by manipulating the 'menu' parameter to access sensitive files like '/proc/self/environ' and '/etc/passwd'. The lack of input sanitization allows arbitrary file reads, potentially leading to information disclosure or remote code execution if combined with log poisoning.
Description
SyCtel Design - 'menu' Multiple Local File Inclusions
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in SyCtel Design by manipulating the 'menu' parameter to access sensitive files like '/proc/self/environ' and '/etc/passwd'. The lack of input sanitization allows arbitrary file reads, potentially leading to information disclosure or remote code execution if combined with log poisoning.