EIP-2026-102512
PRE-CVENortel Contact Recording Centralized Archive 6.5.1 - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102512. PoCs published by rgod.
AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in Nortel Contact Recording Centralized Archive 6.5.1 via the EyrAPIConfiguration web service's getSubKeys() method. It sends a crafted SOAP request to execute arbitrary SQL commands, potentially leading to remote code execution via xp_cmdshell.
Description
Nortel Contact Recording Centralized Archive 6.5.1 - SQL Injection
Exploits (1)
This PHP script exploits a SQL injection vulnerability in Nortel Contact Recording Centralized Archive 6.5.1 via the EyrAPIConfiguration web service's getSubKeys() method. It sends a crafted SOAP request to execute arbitrary SQL commands, potentially leading to remote code execution via xp_cmdshell.