EIP-2026-109894

PRE-CVE

Netvidade engine 1.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109894. PoCs published by pwndomina.

AI-analyzed exploit summary This Perl script exploits multiple SQL injection vulnerabilities in Netvidade engine v1.0 by injecting malicious SQL queries via the 'id' parameter in various PHP scripts. It demonstrates union-based SQLi to extract administrator credentials.

Description

Netvidade engine 1.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by pwndomina · perlwebappsphp
https://www.exploit-db.com/exploits/12550

This Perl script exploits multiple SQL injection vulnerabilities in Netvidade engine v1.0 by injecting malicious SQL queries via the 'id' parameter in various PHP scripts. It demonstrates union-based SQLi to extract administrator credentials.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Netvidade engine v1.0
No auth needed
Prerequisites: Network access to the target web application · Perl environment with LWP::UserAgent and MIME::Base64 modules
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026