EIP-2026-111105

PRE-CVE

PHPKit 1.6.1 R2 - 'overview.php' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111105. PoCs published by Easy Laster.

AI-analyzed exploit summary This Ruby script exploits a SQL injection vulnerability in PHPKit 1.6.1 R2 by injecting crafted SQL queries into the 'letter' parameter of the 'overview.php' file. It extracts user credentials (ID, username, password, email, and status) by leveraging UNION-based SQL injection.

Description

PHPKit 1.6.1 R2 - 'overview.php' SQL Injection

Exploits (1)

exploitdb WORKING POC
by Easy Laster · rubywebappsphp
https://www.exploit-db.com/exploits/15350

This Ruby script exploits a SQL injection vulnerability in PHPKit 1.6.1 R2 by injecting crafted SQL queries into the 'letter' parameter of the 'overview.php' file. It extracts user credentials (ID, username, password, email, and status) by leveraging UNION-based SQL injection.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PHPKit 1.6.1 R2
No auth needed
Prerequisites: Target must be running PHPKit 1.6.1 R2 · Network access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026