EIP-2026-111830
PRE-CVERunCMS 1.6.1 - 'pm.class.php' Multiple SQL Injections
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111830. PoCs published by The:Paradox.
AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in RunCMS <= 1.6.1 by injecting malicious SQL into the 'msg_image' parameter. It extracts user credentials (username and password hash) from the database and sends them via a private message to the attacker's account.
Description
RunCMS 1.6.1 - 'pm.class.php' Multiple SQL Injections
Exploits (1)
This Python script exploits a SQL injection vulnerability in RunCMS <= 1.6.1 by injecting malicious SQL into the 'msg_image' parameter. It extracts user credentials (username and password hash) from the database and sends them via a private message to the attacker's account.