Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105965. PoCs published by Lidloses_Auge.
AI-analyzed exploit summary This PHP script exploits an SQL injection vulnerability in CMS Easyway by manipulating the 'mid' parameter to extract user credentials (login and password hashes) from the database. It automates the process of determining the number of columns and then performs a UNION-based SQL injection to retrieve the data.
Description
CMS Easyway - 'mid' SQL Injection
Exploits (1)
This PHP script exploits an SQL injection vulnerability in CMS Easyway by manipulating the 'mid' parameter to extract user credentials (login and password hashes) from the database. It automates the process of determining the number of columns and then performs a UNION-based SQL injection to retrieve the data.