EIP-2026-109745
PRE-CVEMyBloggie 2.1.6 - HTML Injection / SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109745. PoCs published by Robin Verton.
AI-analyzed exploit summary The code demonstrates a SQL injection and HTML injection vulnerability in myBloggie 2.1.6 due to insufficient input sanitization in the `trackback.php` file. The `validate_url` function uses a weak regex pattern, allowing attackers to bypass URL validation and inject malicious input.
Description
MyBloggie 2.1.6 - HTML Injection / SQL Injection
Exploits (1)
The code demonstrates a SQL injection and HTML injection vulnerability in myBloggie 2.1.6 due to insufficient input sanitization in the `trackback.php` file. The `validate_url` function uses a weak regex pattern, allowing attackers to bypass URL validation and inject malicious input.