EIP-2026-100223

PRE-CVE

Comersus Open Technologies Comersus Cart 6.0.41 - Multiple SQL Injections

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100223. PoCs published by Diabolic Crab.

AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in Comersus Cart, with example URLs demonstrating unsanitized input in the 'name', 'email', and 'idProduct' parameters. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.

Description

Comersus Open Technologies Comersus Cart 6.0.41 - Multiple SQL Injections

Exploits (1)

exploitdb WRITEUP VERIFIED
by Diabolic Crab · textwebappsasp
https://www.exploit-db.com/exploits/25953

The provided text describes SQL injection vulnerabilities in Comersus Cart, with example URLs demonstrating unsanitized input in the 'name', 'email', and 'idProduct' parameters. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Comersus Cart (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Comersus Cart application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026