EIP-2026-109357
PRE-CVEMax.Blog 1.0.6 - 'submit_post.php' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109357. PoCs published by Salvatore Fresta.
AI-analyzed exploit summary This is a technical writeup detailing a SQL injection vulnerability in Max.Blog <= 1.0.6. The vulnerability allows a registered user to extract admin credentials via a crafted UNION-based SQL injection in the 'draft' parameter of submit_post.php when magic quotes are disabled.
Description
Max.Blog 1.0.6 - 'submit_post.php' SQL Injection
Exploits (1)
This is a technical writeup detailing a SQL injection vulnerability in Max.Blog <= 1.0.6. The vulnerability allows a registered user to extract admin credentials via a crafted UNION-based SQL injection in the 'draft' parameter of submit_post.php when magic quotes are disabled.