EIP-2026-111124
PRE-CVEPHPLive 4.4.8 < 4.5.4 - Password Recovery SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111124. PoCs published by Tiago Carvalho.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in PhpLive versions 4.4.8 to 4.5.4, specifically in the password recovery process. It bypasses authentication by injecting a UNION-based SQL query to reset passwords and retrieve usernames for both admin and operator accounts.
Description
PHPLive 4.4.8 < 4.5.4 - Password Recovery SQL Injection
Exploits (1)
This exploit leverages a SQL injection vulnerability in PhpLive versions 4.4.8 to 4.5.4, specifically in the password recovery process. It bypasses authentication by injecting a UNION-based SQL query to reset passwords and retrieve usernames for both admin and operator accounts.