EIP-2026-106417

PRE-CVE

Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106417. PoCs published by Mesut Cetin.

AI-analyzed exploit summary This exploit demonstrates a UNION-based SQL injection vulnerability in the 'date' POST parameter of the Dental Clinic Appointment Reservation System 1.0. The payload retrieves sensitive data such as usernames, passwords, and database versions from the 'users' table.

Description

Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated)

Exploits (1)

exploitdb WORKING POC
by Mesut Cetin · textwebappsphp
https://www.exploit-db.com/exploits/49861

This exploit demonstrates a UNION-based SQL injection vulnerability in the 'date' POST parameter of the Dental Clinic Appointment Reservation System 1.0. The payload retrieves sensitive data such as usernames, passwords, and database versions from the 'users' table.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dental Clinic Appointment Reservation System 1.0
Auth required
Prerequisites: Authenticated session (PHPSESSID cookie) · Access to the admin/sort_date.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026