EIP-2026-119360

PRE-CVE

DirectControlTM 3.1.7.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119360. PoCs published by mohamad ch.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in DirectControlTM Version 3.1.7.0, including SQL injection, arbitrary file upload, CSRF, and XSS. It provides functional payloads and HTTP requests to exploit these vulnerabilities.

Description

DirectControlTM 3.1.7.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by mohamad ch · textwebappswindows
https://www.exploit-db.com/exploits/30669

The exploit demonstrates multiple vulnerabilities in DirectControlTM Version 3.1.7.0, including SQL injection, arbitrary file upload, CSRF, and XSS. It provides functional payloads and HTTP requests to exploit these vulnerabilities.

Classification
Working Poc 95%
Attack Type
Sqli | Xss | Auth Bypass | Other
Complexity
Trivial
Reliability
Reliable
Target: DirectControlTM Version 3.1.7.0
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026