Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-111175. PoCs published by WhiteCollarGroup.
AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in PHPNet <= 1.8 via the 'ler.php' file, allowing an attacker to extract MySQL user credentials and other sensitive information. It also documents additional vulnerabilities such as login bypass, arbitrary file upload, and XSS.
Description
PHPNet 1.8 - 'ler.php' SQL Injection
Exploits (1)
This PHP script exploits a SQL injection vulnerability in PHPNet <= 1.8 via the 'ler.php' file, allowing an attacker to extract MySQL user credentials and other sensitive information. It also documents additional vulnerabilities such as login bypass, arbitrary file upload, and XSS.