EIP-2026-105996

PRE-CVE

CMS Openpage - 'index.php' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105996. PoCs published by Phenom.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CMS Openpage's index.php file, specifically in the 'id' parameter when accessing the news page. The provided URL example shows how to extract user credentials (username, password, email) from the 'utenti' table using a UNION-based SQL injection.

Description

CMS Openpage - 'index.php' SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by Phenom · textwebappsphp
https://www.exploit-db.com/exploits/11836

This exploit demonstrates a SQL injection vulnerability in CMS Openpage's index.php file, specifically in the 'id' parameter when accessing the news page. The provided URL example shows how to extract user credentials (username, password, email) from the 'utenti' table using a UNION-based SQL injection.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: CMS Openpage
No auth needed
Prerequisites: Access to the vulnerable CMS Openpage instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026