EIP-2026-110871
PRE-CVEPHP-Nuke 8.1.0.3.5b (Your_Account Module) - Blind SQL Injection (Benchmark Mode)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110871. PoCs published by yawn.
AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in PHP-Nuke's Your_Account module by leveraging benchmark-based timing attacks to extract the admin password hash. It uses LWP::UserAgent to send crafted requests and measures response times to infer character values.
Description
PHP-Nuke 8.1.0.3.5b (Your_Account Module) - Blind SQL Injection (Benchmark Mode)
Exploits (1)
This exploit targets a blind SQL injection vulnerability in PHP-Nuke's Your_Account module by leveraging benchmark-based timing attacks to extract the admin password hash. It uses LWP::UserAgent to send crafted requests and measures response times to infer character values.