EIP-2026-106115

PRE-CVE

Computer Laboratory Management System v1.0 - Multiple-SQLi

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106115. PoCs published by nu11secur1ty.

AI-analyzed exploit summary This exploit demonstrates multiple SQL injection techniques (boolean-based blind, error-based, time-based blind, and UNION query) targeting the 'id' parameter in Computer Laboratory Management System v1.0. The payloads are designed to extract data or confirm vulnerability via MySQL functions.

Description

Computer Laboratory Management System v1.0 - Multiple-SQLi

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textwebappsphp
https://www.exploit-db.com/exploits/51965

This exploit demonstrates multiple SQL injection techniques (boolean-based blind, error-based, time-based blind, and UNION query) targeting the 'id' parameter in Computer Laboratory Management System v1.0. The payloads are designed to extract data or confirm vulnerability via MySQL functions.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Computer Laboratory Management System v1.0
No auth needed
Prerequisites: Access to the vulnerable endpoint with the 'id' parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026