Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-107794. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in ImageBay 1.0, allowing an attacker to inject SQL commands via the 'pid' parameter in 'picture.php' and the 'id' parameter in 'updaterate.php'. The provided payload extracts user credentials (username and password) from the 'users' table.
Description
ImageBay 1.0 - SQL Injection
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in ImageBay 1.0, allowing an attacker to inject SQL commands via the 'pid' parameter in 'picture.php' and the 'id' parameter in 'updaterate.php'. The provided payload extracts user credentials (username and password) from the 'users' table.