EIP-2026-106061
PRE-CVECollege Notes Management System 1.0 - 'user' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106061. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in College Notes Management System 1.0 via the 'user' parameter in login.php. The payload bypasses authentication and extracts database information (user, database name, version) through a time-based blind SQLi technique.
Description
College Notes Management System 1.0 - 'user' SQL Injection
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in College Notes Management System 1.0 via the 'user' parameter in login.php. The payload bypasses authentication and extracts database information (user, database name, version) through a time-based blind SQLi technique.