EIP-2026-111928
PRE-CVESchool File Management System 1.0 - 'username' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111928. PoCs published by Tarun Sehgal.
AI-analyzed exploit summary This is a functional SQL injection exploit targeting the 'username' parameter in School File Management System 1.0. The crafted POST request bypasses authentication and leaks database information (name and MariaDB version) via a time-based blind SQLi technique using GROUP BY and HAVING clauses.
Description
School File Management System 1.0 - 'username' SQL Injection
Exploits (1)
This is a functional SQL injection exploit targeting the 'username' parameter in School File Management System 1.0. The crafted POST request bypasses authentication and leaks database information (name and MariaDB version) via a time-based blind SQLi technique using GROUP BY and HAVING clauses.