EIP-2026-106100

PRE-CVE

Comparison Engine Power 1.0 - 'product.comparision.php' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106100. PoCs published by SirGod.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Comparison Engine Power 1.0, allowing an attacker to extract sensitive user data (id, email, password, nickname) from the database via a crafted UNION-based SQL query.

Description

Comparison Engine Power 1.0 - 'product.comparision.php' SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by SirGod · textwebappsphp
https://www.exploit-db.com/exploits/32875

This exploit demonstrates an SQL injection vulnerability in Comparison Engine Power 1.0, allowing an attacker to extract sensitive user data (id, email, password, nickname) from the database via a crafted UNION-based SQL query.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Comparison Engine Power 1.0
No auth needed
Prerequisites: Access to the vulnerable endpoint · Database structure knowledge (table and column names)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026