Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110979. PoCs published by CrazyMouse.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the MyPage plugin for phpBB, allowing an attacker to extract sensitive user data such as usernames and password hashes. The provided URL manipulates the 'id' parameter to perform a time-based blind SQL injection.
Description
phpBB MyPage Plugin - SQL Injection
Exploits (1)
exploitdb
WORKING POC
by CrazyMouse · textwebappsphp
https://www.exploit-db.com/exploits/18212
This exploit demonstrates a SQL injection vulnerability in the MyPage plugin for phpBB, allowing an attacker to extract sensitive user data such as usernames and password hashes. The provided URL manipulates the 'id' parameter to perform a time-based blind SQL injection.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
phpBB MyPage plugin (all versions, including 0.2.3)
No auth needed
Prerequisites:
Access to the target phpBB forum with the MyPage plugin installed · The 'mypage.php' endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026