EIP-2026-106339

PRE-CVE

Daily Expense Manager 1.0 - 'term' SQLi

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106339. PoCs published by Stefan Hesselman.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Daily Expense Manager 1.0 via the 'term' GET parameter. The PoC shows how an attacker can inject malicious SQL queries to extract database information, such as the version, without authentication.

Description

Daily Expense Manager 1.0 - 'term' SQLi

Exploits (1)

exploitdb WORKING POC
by Stefan Hesselman · textwebappsphp
https://www.exploit-db.com/exploits/51973

This exploit demonstrates a SQL injection vulnerability in Daily Expense Manager 1.0 via the 'term' GET parameter. The PoC shows how an attacker can inject malicious SQL queries to extract database information, such as the version, without authentication.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Daily Expense Manager 1.0
No auth needed
Prerequisites: Access to the vulnerable endpoint · Network connectivity to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026