EIP-2026-111201

PRE-CVE

phpSFP Schedule Facebook Posts 1.5.6 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111201. PoCs published by @u0x.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in phpSFP (Schedule Facebook Posts) versions 1.5.6 and 1.4.1. The flaw exists in the 'remember me' functionality, where the 'login' cookie is improperly sanitized, allowing error-based SQL injection to extract user credentials.

Description

phpSFP Schedule Facebook Posts 1.5.6 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by @u0x · textwebappsphp
https://www.exploit-db.com/exploits/36616

This exploit demonstrates an SQL injection vulnerability in phpSFP (Schedule Facebook Posts) versions 1.5.6 and 1.4.1. The flaw exists in the 'remember me' functionality, where the 'login' cookie is improperly sanitized, allowing error-based SQL injection to extract user credentials.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: phpSFP (Schedule Facebook Posts) 1.5.6 and 1.4.1
No auth needed
Prerequisites: Target must have the vulnerable phpSFP version installed · Error-based SQL injection must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026