EIP-2026-118450

PRE-CVE

DzSoft PHP Editor 4.2.7 - File Enumeration

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118450. PoCs published by hyp3rlinx.

AI-analyzed exploit summary The exploit demonstrates a file enumeration vulnerability in DzSoft PHP Editor v4.2.7 by bypassing access controls using HEAD requests with directory traversal sequences. It includes functional Python code to enumerate files outside the webroot.

Description

DzSoft PHP Editor 4.2.7 - File Enumeration

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textremotewindows
https://www.exploit-db.com/exploits/41751

The exploit demonstrates a file enumeration vulnerability in DzSoft PHP Editor v4.2.7 by bypassing access controls using HEAD requests with directory traversal sequences. It includes functional Python code to enumerate files outside the webroot.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: DzSoft PHP Editor v4.2.7
No auth needed
Prerequisites: DzSoft built-in web server running · REMOTE_HOST/REMOTE_ADDR set to a non-localhost IP
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026