EIP-2026-109113
PRE-CVELibrary System 1.0 - 'student_id' SQL injection (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109113. PoCs published by Vinay Bhuria.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Library System 1.0 via the 'student_id' parameter, allowing command execution via SQLMap's --os-shell feature. The PoC includes payloads for boolean-based blind, error-based, time-based blind, and UNION-based SQLi.
Description
Library System 1.0 - 'student_id' SQL injection (Authenticated)
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in Library System 1.0 via the 'student_id' parameter, allowing command execution via SQLMap's --os-shell feature. The PoC includes payloads for boolean-based blind, error-based, time-based blind, and UNION-based SQLi.