EIP-2026-118447

PRE-CVE

DWebPro 6.8.26 - Directory Traversal / Arbitrary File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118447. PoCs published by Alfons Luja.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in DWebPro, allowing attackers to access arbitrary files by manipulating URL paths with encoded sequences. The PoC includes example URLs that traverse directories to access sensitive files like those in the WINDOWS directory.

Description

DWebPro 6.8.26 - Directory Traversal / Arbitrary File Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alfons Luja · textremotewindows
https://www.exploit-db.com/exploits/32957

This exploit demonstrates a directory traversal vulnerability in DWebPro, allowing attackers to access arbitrary files by manipulating URL paths with encoded sequences. The PoC includes example URLs that traverse directories to access sensitive files like those in the WINDOWS directory.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: DWebPro 6.8.26
No auth needed
Prerequisites: Network access to the target DWebPro server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026