EIP-2026-107935

PRE-CVE

Invision Power Board 3.0.1 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107935. PoCs published by Cryptovirus.

AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in IPB (Invision Power Board) 3.0.1 by manipulating POST parameters to extract user credentials (usernames and password hashes) via blind SQL injection techniques. It includes functionality for authentication, target validation, and data extraction.

Description

Invision Power Board 3.0.1 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Cryptovirus · phpwebappsphp
https://www.exploit-db.com/exploits/12586

This PHP script exploits a SQL injection vulnerability in IPB (Invision Power Board) 3.0.1 by manipulating POST parameters to extract user credentials (usernames and password hashes) via blind SQL injection techniques. It includes functionality for authentication, target validation, and data extraction.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Power Board 3.0.1
Auth required
Prerequisites: Target URL · User ID · Optional login credentials for authenticated forums
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026