EIP-2026-110342
PRE-CVEOrderSys 1.6.4 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110342. PoCs published by Canberk BOLAT.
AI-analyzed exploit summary The provided code demonstrates multiple SQL injection and XSS vulnerabilities in OrderSys 1.6.4 by including crafted URLs that exploit unsanitized input parameters. The SQLi payloads use time-based techniques (e.g., sleep(25)), while XSS payloads inject malicious scripts.
Description
OrderSys 1.6.4 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The provided code demonstrates multiple SQL injection and XSS vulnerabilities in OrderSys 1.6.4 by including crafted URLs that exploit unsanitized input parameters. The SQLi payloads use time-based techniques (e.g., sleep(25)), while XSS payloads inject malicious scripts.