EIP-2026-107904
PRE-CVEInvision Community Blog 1.0/1.1 - Multiple Input Validation Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107904. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided code demonstrates SQL injection and XSS vulnerabilities in Invision Community Blog by exploiting unsanitized input in the 'eid', 'cid', and 'mid' parameters. The SQLi payloads extract user data from the 'ibf_members' table, while the XSS payload is implied via the 'mid' parameter.
Description
Invision Community Blog 1.0/1.1 - Multiple Input Validation Vulnerabilities
Exploits (1)
The provided code demonstrates SQL injection and XSS vulnerabilities in Invision Community Blog by exploiting unsanitized input in the 'eid', 'cid', and 'mid' parameters. The SQLi payloads extract user data from the 'ibf_members' table, while the XSS payload is implied via the 'mid' parameter.