EIP-2026-105090
PRE-CVEAlienvault 4.5.0 - (Authenticated) SQL Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105090. PoCs published by Brandon Perry.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in AlienVault 4.5.0, allowing arbitrary file reads via a crafted GET request to the ISO27001Bar1.php endpoint. The Metasploit module automates the attack by leveraging time-based SQL injection to exfiltrate file contents.
Description
Alienvault 4.5.0 - (Authenticated) SQL Injection (Metasploit)
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in AlienVault 4.5.0, allowing arbitrary file reads via a crafted GET request to the ISO27001Bar1.php endpoint. The Metasploit module automates the attack by leveraging time-based SQL injection to exfiltrate file contents.