EIP-2026-114373
PRE-CVEWoW Roster 1.70 - '/lib/phpBB.php' Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114373. PoCs published by |peti.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in WoW Roster's phpbb.php script, allowing an attacker to include and execute arbitrary remote code via the 'subdir' parameter. The exploit is straightforward and leverages a common RFI attack vector.
Description
WoW Roster 1.70 - '/lib/phpBB.php' Remote File Inclusion
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by |peti · textwebappsphp
https://www.exploit-db.com/exploits/2109
This exploit demonstrates a Remote File Include (RFI) vulnerability in WoW Roster's phpbb.php script, allowing an attacker to include and execute arbitrary remote code via the 'subdir' parameter. The exploit is straightforward and leverages a common RFI attack vector.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
World of Warcraft (WoW) Roster version 1.*
No auth needed
Prerequisites:
Target server with vulnerable WoW Roster installation · Remote server hosting malicious PHP code
mistral-large-3 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026