EIP-2026-112878

PRE-CVE

Ultimate PHP Board 1.0 final Beta - 'viewtopic.php' Directory Contents Browsing

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112878. PoCs published by euronymous.

AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in Ultimate PHP Board (UPB) via a crafted request to viewtopic.php, leading to information disclosure of directory contents and file paths. The vulnerability arises from improper handling of user-supplied input in the 'id' parameter, resulting in error messages that leak sensitive path information.

Description

Ultimate PHP Board 1.0 final Beta - 'viewtopic.php' Directory Contents Browsing

Exploits (1)

exploitdb WRITEUP VERIFIED
by euronymous · textwebappsphp
https://www.exploit-db.com/exploits/22075

The exploit demonstrates a directory traversal vulnerability in Ultimate PHP Board (UPB) via a crafted request to viewtopic.php, leading to information disclosure of directory contents and file paths. The vulnerability arises from improper handling of user-supplied input in the 'id' parameter, resulting in error messages that leak sensitive path information.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Ultimate PHP Board (UPB)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026