EIP-2026-110112

PRE-CVE

Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110112. PoCs published by Gian Paris C. Agsam.

AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Online Hotel Booking In PHP 1.0, allowing unauthenticated extraction of the admin password via time-based techniques. It uses a character-by-character brute-force approach with sleep-based payloads.

Description

Online Hotel Booking In PHP 1.0 - Blind SQL Injection (Unauthenticated)

Exploits (1)

exploitdb WORKING POC
by Gian Paris C. Agsam · pythonwebappsphp
https://www.exploit-db.com/exploits/51938

This exploit demonstrates a blind SQL injection vulnerability in Online Hotel Booking In PHP 1.0, allowing unauthenticated extraction of the admin password via time-based techniques. It uses a character-by-character brute-force approach with sleep-based payloads.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Online Hotel Booking In PHP 1.0
No auth needed
Prerequisites: Target URL with vulnerable login endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026