EIP-2026-107490
PRE-CVEGreatclone GC Auction Platinum - 'category.php' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107490. PoCs published by Hussin X.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in GC Auction Platinum by injecting a UNION-based query to extract admin credentials (username and password) from the database. The payload is appended to the 'cate_id' parameter in the URL, leveraging improper input sanitization.
Description
Greatclone GC Auction Platinum - 'category.php' SQL Injection
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in GC Auction Platinum by injecting a UNION-based query to extract admin credentials (username and password) from the database. The payload is appended to the 'cate_id' parameter in the URL, leveraging improper input sanitization.