Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-118450. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit demonstrates a file enumeration vulnerability in DzSoft PHP Editor v4.2.7 by bypassing access controls using HEAD requests with directory traversal sequences. It includes functional Python code to enumerate files outside the webroot.
Description
DzSoft PHP Editor 4.2.7 - File Enumeration
Exploits (1)
exploitdb
WORKING POC
by hyp3rlinx · textremotewindows
https://www.exploit-db.com/exploits/41751
The exploit demonstrates a file enumeration vulnerability in DzSoft PHP Editor v4.2.7 by bypassing access controls using HEAD requests with directory traversal sequences. It includes functional Python code to enumerate files outside the webroot.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
DzSoft PHP Editor v4.2.7
No auth needed
Prerequisites:
DzSoft built-in web server running · REMOTE_HOST/REMOTE_ADDR set to a non-localhost IP
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026