EIP-2026-100629

PRE-CVE

WebWiz Products 1.0/3.06 - Authentication Bypass / SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100629. PoCs published by DevilBox.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in WebWiz scripts, allowing authentication bypass via crafted input in the login form. The PoC uses SQLi to bypass authentication by injecting a UNION-based query.

Description

WebWiz Products 1.0/3.06 - Authentication Bypass / SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by DevilBox · textwebappsasp
https://www.exploit-db.com/exploits/1399

This exploit demonstrates an SQL injection vulnerability in WebWiz scripts, allowing authentication bypass via crafted input in the login form. The PoC uses SQLi to bypass authentication by injecting a UNION-based query.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WebWiz Site News, Journal, Weekly Poll, Database Login (Access 2000/97) versions 3.06 and prior
No auth needed
Prerequisites: Target application must be running a vulnerable version of WebWiz scripts
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026