EIP-2026-107961

PRE-CVE

iScripts EasyCreate 3.2 - 'siteid' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107961. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iScripts EasyCreate v3.2. The vulnerability allows an attacker to inject malicious SQL queries via the 'siteid' parameter in the 'getsitedetails.php' script, potentially leading to unauthorized data access or manipulation.

Description

iScripts EasyCreate 3.2 - 'siteid' SQL Injection

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/41252

This exploit demonstrates a SQL injection vulnerability in iScripts EasyCreate v3.2. The vulnerability allows an attacker to inject malicious SQL queries via the 'siteid' parameter in the 'getsitedetails.php' script, potentially leading to unauthorized data access or manipulation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: iScripts EasyCreate v3.2
Auth required
Prerequisites: Valid user credentials to log in as a regular user
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026