EIP-2026-107580
PRE-CVEHelpDeskZ < 1.0.2 - (Authenticated) SQL Injection / Unauthorized File Download
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107580. PoCs published by Mariusz Poplawski.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in HelpDeskZ <= v1.0.2, allowing an attacker to retrieve administrator credentials by manipulating the 'msg_id' parameter in the attachment download functionality. The script automates the extraction of the database table prefix and admin credentials via blind SQL injection.
Description
HelpDeskZ < 1.0.2 - (Authenticated) SQL Injection / Unauthorized File Download
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in HelpDeskZ <= v1.0.2, allowing an attacker to retrieve administrator credentials by manipulating the 'msg_id' parameter in the attachment download functionality. The script automates the extraction of the database table prefix and admin credentials via blind SQL injection.