Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105322. PoCs published by GulfTech Security.
AI-analyzed exploit summary The writeup describes an SQL injection vulnerability in AutoRank PHP <= 2.0.4, where malicious input in user, password, email, or username fields can bypass authentication and expose plaintext passwords. The affected file is accounts.php.
Description
AutoRank PHP < 2.0.4 - SQL Injection (PoC)
Exploits (1)
exploitdb
WRITEUP
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/43792
The writeup describes an SQL injection vulnerability in AutoRank PHP <= 2.0.4, where malicious input in user, password, email, or username fields can bypass authentication and expose plaintext passwords. The affected file is accounts.php.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
AutoRank PHP <= 2.0.4
No auth needed
Prerequisites:
Access to the login, registration, or password recovery functionality
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026