EIP-2026-113224

PRE-CVE

Web Service Deluxe News Manager 1.0.1 Deluxe - 'footer.php' Local File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113224. PoCs published by BeyazKurt.

AI-analyzed exploit summary This Perl script exploits a local file inclusion vulnerability in News Manager Deluxe 1.0.1 by injecting malicious code into Apache log files and then including them via the 'template' parameter in footer.php. It provides a shell-like interface to execute commands on the target system.

Description

Web Service Deluxe News Manager 1.0.1 Deluxe - 'footer.php' Local File Inclusion

Exploits (1)

exploitdb WORKING POC VERIFIED
by BeyazKurt · perlwebappsphp
https://www.exploit-db.com/exploits/29862

This Perl script exploits a local file inclusion vulnerability in News Manager Deluxe 1.0.1 by injecting malicious code into Apache log files and then including them via the 'template' parameter in footer.php. It provides a shell-like interface to execute commands on the target system.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: News Manager Deluxe 1.0.1
No auth needed
Prerequisites: Target must be running News Manager Deluxe 1.0.1 · Apache log files must be writable · Attacker must be able to reach the target's web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026