Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-113236. PoCs published by Giuseppe D'Inverno.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Web@all CMS <= 1.1 by allowing an attacker to change admin credentials via a crafted POST request to 'mem/action.php'. The exploit leverages hidden form fields to manipulate user data without proper authentication checks.
Description
Web@all 1.1 - Remote Admin Settings Change
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Web@all CMS <= 1.1 by allowing an attacker to change admin credentials via a crafted POST request to 'mem/action.php'. The exploit leverages hidden form fields to manipulate user data without proper authentication checks.