EIP-2026-112707
PRE-CVETinyCMS 1.3 - 'index.php?page' Traversal Local File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112707. PoCs published by KedAns-Dz.
AI-analyzed exploit summary The provided code demonstrates a Local File Inclusion (LFI) vulnerability in TinyCMS 1.3 by exploiting improper input validation in the 'page' parameter. The PoC includes a simple HTML form that submits a crafted request to include arbitrary local files via directory traversal sequences.
Description
TinyCMS 1.3 - 'index.php?page' Traversal Local File Inclusion
Exploits (1)
The provided code demonstrates a Local File Inclusion (LFI) vulnerability in TinyCMS 1.3 by exploiting improper input validation in the 'page' parameter. The PoC includes a simple HTML form that submits a crafted request to include arbitrary local files via directory traversal sequences.