EIP-2026-112544
PRE-CVETA.CMS (TeachArabia) - 'lang' Traversal Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112544. PoCs published by CoBRa_21.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in TA.CMS by manipulating the 'lang' parameter to traverse directories and access arbitrary files (e.g., /etc/passwd). The 'p_id' parameter is also mentioned as a potential SQL injection vector, though no explicit SQLi payload is provided.
Description
TA.CMS (TeachArabia) - 'lang' Traversal Local File Inclusion
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in TA.CMS by manipulating the 'lang' parameter to traverse directories and access arbitrary files (e.g., /etc/passwd). The 'p_id' parameter is also mentioned as a potential SQL injection vector, though no explicit SQLi payload is provided.