EIP-2026-113284

PRE-CVE

Webfroot Shoutbox 2.32 - 'URI' File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113284. PoCs published by pokleyzz.

AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in Shoutbox due to insufficient sanitization of the 'conf' URI parameter. An attacker can manipulate this parameter to read arbitrary files accessible by the web server, such as '/etc/passwd'.

Description

Webfroot Shoutbox 2.32 - 'URI' File Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by pokleyzz · textwebappsphp
https://www.exploit-db.com/exploits/22671

The exploit demonstrates a directory traversal vulnerability in Shoutbox due to insufficient sanitization of the 'conf' URI parameter. An attacker can manipulate this parameter to read arbitrary files accessible by the web server, such as '/etc/passwd'.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Shoutbox (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable Shoutbox application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026