EIP-2026-109520

PRE-CVE

Mnews 1.1 - 'view.php' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109520. PoCs published by WhiteCollarGroup.

AI-analyzed exploit summary This PHP script exploits an SQL injection vulnerability in Mnews <= 1.1 by injecting malicious SQL queries via the 'id' parameter in view.php. It extracts MySQL user credentials and version information, as well as admin login details from the database.

Description

Mnews 1.1 - 'view.php' SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by WhiteCollarGroup · phpwebappsphp
https://www.exploit-db.com/exploits/18983

This PHP script exploits an SQL injection vulnerability in Mnews <= 1.1 by injecting malicious SQL queries via the 'id' parameter in view.php. It extracts MySQL user credentials and version information, as well as admin login details from the database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Mnews <= 1.1
No auth needed
Prerequisites: Target must be running Mnews <= 1.1 · Target must be accessible via HTTP · Target must not have Apache mod_security or similar protections
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026