EIP-2026-109231

PRE-CVE

Lyrist - 'id' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109231. PoCs published by Meisam Monsef.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Lyrist - Music Lyrics Script. The PoC shows how an attacker can inject SQL commands into the 'id' parameter of the lyrics.php page to extract data from the database.

Description

Lyrist - 'id' SQL Injection

Exploits (1)

exploitdb WORKING POC
by Meisam Monsef · textwebappsphp
https://www.exploit-db.com/exploits/44772

This exploit demonstrates a SQL injection vulnerability in Lyrist - Music Lyrics Script. The PoC shows how an attacker can inject SQL commands into the 'id' parameter of the lyrics.php page to extract data from the database.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Lyrist - Music Lyrics Script (All Versions)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026