EIP-2026-109208
PRE-CVELore 1.5.6 - 'article.php' Blind SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109208. PoCs published by OzX.
AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Lore CMS version 1.5.6 by leveraging the 'article.php?id=' parameter and the 'Add Comment' feature. It automates the extraction of usernames and passwords from the 'lore_users' table using time-based blind SQLi techniques.
Description
Lore 1.5.6 - 'article.php' Blind SQL Injection
Exploits (1)
This PHP script exploits a blind SQL injection vulnerability in Lore CMS version 1.5.6 by leveraging the 'article.php?id=' parameter and the 'Add Comment' feature. It automates the extraction of usernames and passwords from the 'lore_users' table using time-based blind SQLi techniques.