EIP-2026-114497
PRE-CVEYABB SE 0.8/1.4/1.5 - 'Packages.php' Remote File Inclusion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114497. PoCs published by spabam.
AI-analyzed exploit summary This Perl script exploits a file inclusion vulnerability in YaBB SE by manipulating the 'sourcedir' parameter to include and execute an external file, allowing remote command execution. The exploit establishes a socket connection to the target and sends crafted HTTP requests to trigger the vulnerability.
Description
YABB SE 0.8/1.4/1.5 - 'Packages.php' Remote File Inclusion
Exploits (1)
This Perl script exploits a file inclusion vulnerability in YaBB SE by manipulating the 'sourcedir' parameter to include and execute an external file, allowing remote command execution. The exploit establishes a socket connection to the target and sends crafted HTTP requests to trigger the vulnerability.