EIP-2026-109894
PRE-CVENetvidade engine 1.0 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109894. PoCs published by pwndomina.
AI-analyzed exploit summary This Perl script exploits multiple SQL injection vulnerabilities in Netvidade engine v1.0 by injecting malicious SQL queries via the 'id' parameter in various PHP scripts. It demonstrates union-based SQLi to extract administrator credentials.
Description
Netvidade engine 1.0 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by pwndomina · perlwebappsphp
https://www.exploit-db.com/exploits/12550
This Perl script exploits multiple SQL injection vulnerabilities in Netvidade engine v1.0 by injecting malicious SQL queries via the 'id' parameter in various PHP scripts. It demonstrates union-based SQLi to extract administrator credentials.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Netvidade engine v1.0
No auth needed
Prerequisites:
Network access to the target web application · Perl environment with LWP::UserAgent and MIME::Base64 modules
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026