EIP-2026-111588
PRE-CVEPunBB Automatic Image Upload 1.3.5 - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111588. PoCs published by Dante90.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in PunBB Automatic Image Upload <= v1.3.5 by leveraging an unauthenticated UNION-based SQLi to extract user credentials (username, password, email) from the database. It requires prior authentication and a specific configuration in 'uploadimg_config.php' to be effective.
Description
PunBB Automatic Image Upload 1.3.5 - SQL Injection
Exploits (1)
This Perl script exploits a SQL injection vulnerability in PunBB Automatic Image Upload <= v1.3.5 by leveraging an unauthenticated UNION-based SQLi to extract user credentials (username, password, email) from the database. It requires prior authentication and a specific configuration in 'uploadimg_config.php' to be effective.