EIP-2026-100193
PRE-CVECartWIZ 1.10 - 'searchresults.asp' PriceTo Argument SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100193. PoCs published by Dcrab.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in CartWIZ, where the 'priceTo' parameter in a search query is not properly sanitized. This allows attackers to inject malicious SQL queries, potentially leading to data compromise or further exploitation of the database.
Description
CartWIZ 1.10 - 'searchresults.asp' PriceTo Argument SQL Injection
Exploits (1)
The provided text describes an SQL injection vulnerability in CartWIZ, where the 'priceTo' parameter in a search query is not properly sanitized. This allows attackers to inject malicious SQL queries, potentially leading to data compromise or further exploitation of the database.