Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110217. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OPAC EasyWeb Five 5.7 via the 'nome' parameter. It uses UNION-based techniques to extract database information, including table and column names, and leverages MySQL functions like export_set and CONCAT_WS for data exfiltration.
Description
OPAC EasyWeb Five 5.7 - 'nome' SQL Injection
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in OPAC EasyWeb Five 5.7 via the 'nome' parameter. It uses UNION-based techniques to extract database information, including table and column names, and leverages MySQL functions like export_set and CONCAT_WS for data exfiltration.