EIP-2026-104434

PRE-CVE

SISQUALWFM 7.1.319.103 - Host Header Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104434. PoCs published by Omer Shaik.

AI-analyzed exploit summary This PoC demonstrates a Host Header Injection vulnerability in SISQUALWFM 7.1.319.103, where manipulating the Host header in requests to /sisqualIdentityServer/core/login redirects users to an attacker-controlled domain. The exploit shows the original and modified requests, proving the vulnerability's existence.

Description

SISQUALWFM 7.1.319.103 - Host Header Injection

Exploits (1)

exploitdb WORKING POC
by Omer Shaik · textwebappsmultiple
https://www.exploit-db.com/exploits/51796

This PoC demonstrates a Host Header Injection vulnerability in SISQUALWFM 7.1.319.103, where manipulating the Host header in requests to /sisqualIdentityServer/core/login redirects users to an attacker-controlled domain. The exploit shows the original and modified requests, proving the vulnerability's existence.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: SISQUALWFM 7.1.319.103
No auth needed
Prerequisites: Access to the target application · Ability to intercept/modify HTTP requests (e.g., via Burp Proxy)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026