EIP-2026-105878
PRE-CVEClanTiger < 1.1.1 - Multiple Insecure Cookie Handling Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-105878. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in ClanTiger CMS 1.1, including BBCode bypass leading to XSS and cookie stealing, as well as SQL injection for authentication bypass. The PoC includes payloads for both XSS and SQLi attacks.
Description
ClanTiger < 1.1.1 - Multiple Insecure Cookie Handling Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by YEnH4ckEr · textwebappsphp
https://www.exploit-db.com/exploits/8471
This exploit demonstrates multiple vulnerabilities in ClanTiger CMS 1.1, including BBCode bypass leading to XSS and cookie stealing, as well as SQL injection for authentication bypass. The PoC includes payloads for both XSS and SQLi attacks.
Classification
Working Poc 95%
Attack Type
Xss | Sqli | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
ClanTiger CMS 1.1
No auth needed
Prerequisites:
gpc_magic_quotes=off · DB_PREFIX may need to be empty
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026