EIP-2026-106799

PRE-CVE

EggAvatar for vBulletin 3.8.x - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106799. PoCs published by DSecurity.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in the EggAvatar plugin for vBulletin 3.8.x. It performs authenticated SQLi via the 'eggavatar' parameter to extract database information, user credentials, and other sensitive data.

Description

EggAvatar for vBulletin 3.8.x - SQL Injection

Exploits (1)

exploitdb WORKING POC
by DSecurity · perlwebappsphp
https://www.exploit-db.com/exploits/16934

This Perl script exploits a SQL injection vulnerability in the EggAvatar plugin for vBulletin 3.8.x. It performs authenticated SQLi via the 'eggavatar' parameter to extract database information, user credentials, and other sensitive data.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: vBulletin 3.8.x with EggAvatar plugin 2.3.2
Auth required
Prerequisites: Valid vBulletin credentials · EggAvatar plugin installed · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026