Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109701. PoCs published by Curesec Research Team.
AI-analyzed exploit summary This is a detailed technical writeup describing a second-order SQL injection vulnerability in MyBB 1.8.6, where an authenticated admin can inject malicious SQL into the 'threadsperpage' setting, leading to information disclosure. The proof-of-concept demonstrates the injection via the LIMIT clause, but the primary content is a thorough analysis rather than functional exploit code.
Description
MyBB 1.8.6 - SQL Injection
Exploits (1)
This is a detailed technical writeup describing a second-order SQL injection vulnerability in MyBB 1.8.6, where an authenticated admin can inject malicious SQL into the 'threadsperpage' setting, leading to information disclosure. The proof-of-concept demonstrates the injection via the LIMIT clause, but the primary content is a thorough analysis rather than functional exploit code.