EIP-2026-105271
PRE-CVEASPapp Knowledge Base - 'CatId' SQL Injection (2)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105271. PoCs published by Crackers_Child.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in the 'content_by_cat.asp' page, allowing an attacker to extract user credentials (password, accesslevel, user_name) from the database via UNION-based SQLi. The payloads manipulate the 'contentid' and 'catid' parameters to bypass authentication and dump sensitive data.
Description
ASPapp Knowledge Base - 'CatId' SQL Injection (2)
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in the 'content_by_cat.asp' page, allowing an attacker to extract user credentials (password, accesslevel, user_name) from the database via UNION-based SQLi. The payloads manipulate the 'contentid' and 'catid' parameters to bypass authentication and dump sensitive data.