EIP-2026-106942
PRE-CVEEvernew Free Joke Script 1.2 - Remote Change Password
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106942. PoCs published by Hakxer.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Evernew Free Joke Script 1.2, allowing an attacker to remotely change the admin password due to improper input sanitization in the 'change.php' file.
Description
Evernew Free Joke Script 1.2 - Remote Change Password
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Hakxer · htmlwebappsphp
https://www.exploit-db.com/exploits/8956
This exploit demonstrates a SQL injection vulnerability in Evernew Free Joke Script 1.2, allowing an attacker to remotely change the admin password due to improper input sanitization in the 'change.php' file.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Evernew Free Joke Script 1.2
No auth needed
Prerequisites:
Access to the vulnerable 'change.php' endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026