EIP-2026-100445
PRE-CVEMuOnline Loopholes Web Server - 'pkok.asp' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100445. PoCs published by nukedx.
AI-analyzed exploit summary This is a functional SQL injection (SQLi) exploit targeting a vulnerable web application. It demonstrates how to manipulate character data, vault items, and account passwords via crafted SQL queries in the 'pass' parameter of a POST request.
Description
MuOnline Loopholes Web Server - 'pkok.asp' SQL Injection
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by nukedx · htmlwebappsasp
https://www.exploit-db.com/exploits/1252
This is a functional SQL injection (SQLi) exploit targeting a vulnerable web application. It demonstrates how to manipulate character data, vault items, and account passwords via crafted SQL queries in the 'pass' parameter of a POST request.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Unknown web application (likely a game server with pkok.asp endpoint)
No auth needed
Prerequisites:
Access to the vulnerable web endpoint · Knowledge of target account/character names
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026