EIP-2026-111826
PRE-CVERunCMS 1.1/1.2 Module Newbb_plus/Messages - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111826. PoCs published by GulfTech Security.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in RunCMS by injecting malicious SQL queries via URL parameters. It targets multiple endpoints in the 'newbb_plus' and 'messages' modules to extract user credentials (e.g., 'pass', 'uname') from the 'runcms_users' table.
Description
RunCMS 1.1/1.2 Module Newbb_plus/Messages - SQL Injection
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in RunCMS by injecting malicious SQL queries via URL parameters. It targets multiple endpoints in the 'newbb_plus' and 'messages' modules to extract user credentials (e.g., 'pass', 'uname') from the 'runcms_users' table.