EIP-2026-110716
PRE-CVEPHP Link Directory Software - 'sbcat_id' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110716. PoCs published by h4ck3r.
AI-analyzed exploit summary This is a functional SQL injection exploit for PHP Link Directory software, demonstrating unauthenticated extraction of admin credentials via a crafted `sbcat_id` parameter in `showcats.php`. The PoC uses a UNION-based attack to dump usernames and passwords from the `sblnk_admin` table.
Description
PHP Link Directory Software - 'sbcat_id' SQL Injection
Exploits (1)
This is a functional SQL injection exploit for PHP Link Directory software, demonstrating unauthenticated extraction of admin credentials via a crafted `sbcat_id` parameter in `showcats.php`. The PoC uses a UNION-based attack to dump usernames and passwords from the `sblnk_admin` table.