EIP-2026-100219

PRE-CVE

Comersus Backoffice 4.x/5.0/6.0 - '/comersus/database/comersus.mdb' Direct Request Database Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100219. PoCs published by _6mO_HaCk.

AI-analyzed exploit summary This Perl script exploits multiple vulnerabilities in Comersus BackOfficePlus and BackOfficeLite, including SQL injection for authentication bypass, information disclosure via direct database access, and XSS. It automates checks for these vulnerabilities and includes a brute-force attack capability.

Description

Comersus Backoffice 4.x/5.0/6.0 - '/comersus/database/comersus.mdb' Direct Request Database Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by _6mO_HaCk · perlwebappsasp
https://www.exploit-db.com/exploits/26445

This Perl script exploits multiple vulnerabilities in Comersus BackOfficePlus and BackOfficeLite, including SQL injection for authentication bypass, information disclosure via direct database access, and XSS. It automates checks for these vulnerabilities and includes a brute-force attack capability.

Classification
Working Poc 90%
Attack Type
Sqli | Auth Bypass | Info Leak | Xss
Complexity
Moderate
Reliability
Reliable
Target: Comersus BackOfficePlus and BackOfficeLite (versions 4.2, 4.5, 4.10, 4.11, 4.30, 4.32, 5.0, 5.09, 6.0, 6.0.1)
No auth needed
Prerequisites: Network access to the target · Knowledge of the target path for Comersus installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026