EIP-2026-105912

PRE-CVE

Client Details System 1.0 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105912. PoCs published by Hamdi Sevben.

AI-analyzed exploit summary This exploit demonstrates SQL injection in Client Details System 1.0 via the 'uemail' parameter. It includes sqlmap commands to dump the database, confirming the vulnerability with multiple payload types (boolean-based, error-based, time-based, and UNION queries).

Description

Client Details System 1.0 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Hamdi Sevben · textwebappsphp
https://www.exploit-db.com/exploits/51880

This exploit demonstrates SQL injection in Client Details System 1.0 via the 'uemail' parameter. It includes sqlmap commands to dump the database, confirming the vulnerability with multiple payload types (boolean-based, error-based, time-based, and UNION queries).

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Client Details System 1.0
No auth needed
Prerequisites: Access to the login page · Intercepting proxy like Burp Suite · sqlmap installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026