EIP-2026-110979

PRE-CVE

phpBB MyPage Plugin - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110979. PoCs published by CrazyMouse.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the MyPage plugin for phpBB, allowing an attacker to extract sensitive user data such as usernames and password hashes. The provided URL manipulates the 'id' parameter to perform a time-based blind SQL injection.

Description

phpBB MyPage Plugin - SQL Injection

Exploits (1)

exploitdb WORKING POC
by CrazyMouse · textwebappsphp
https://www.exploit-db.com/exploits/18212

This exploit demonstrates a SQL injection vulnerability in the MyPage plugin for phpBB, allowing an attacker to extract sensitive user data such as usernames and password hashes. The provided URL manipulates the 'id' parameter to perform a time-based blind SQL injection.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: phpBB MyPage plugin (all versions, including 0.2.3)
No auth needed
Prerequisites: Access to the target phpBB forum with the MyPage plugin installed · The 'mypage.php' endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026