EIP-2026-109468

PRE-CVE

MileHigh Creative - SQL Injection / Cross-Site Scripting / HTML Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109468. PoCs published by XroGuE.

AI-analyzed exploit summary This document describes multiple vulnerabilities (SQLi, XSS, HTML injection) in MileHigh Creative's web applications, providing demo URLs and basic exploitation examples. It lacks functional exploit code but includes technical details about vulnerable parameters and attack vectors.

Description

MileHigh Creative - SQL Injection / Cross-Site Scripting / HTML Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by XroGuE · textwebappsphp
https://www.exploit-db.com/exploits/12792

This document describes multiple vulnerabilities (SQLi, XSS, HTML injection) in MileHigh Creative's web applications, providing demo URLs and basic exploitation examples. It lacks functional exploit code but includes technical details about vulnerable parameters and attack vectors.

Classification
Writeup 90%
Attack Type
Sqli | Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MileHigh Creative (contentPage.php, displayResource.php, contentFolder.php)
No auth needed
Prerequisites: Access to vulnerable web application endpoints
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026