EIP-2026-112398

PRE-CVE

Sports Accelerator Suite 2.0 - 'news_id' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112398. PoCs published by LiquidWorm.

AI-analyzed exploit summary This advisory details a SQL injection vulnerability in Sports Accelerator Suite v2.0, where the 'news_id' parameter in 'show_news.php' fails to sanitize user input, allowing attackers to execute arbitrary SQL queries. The document includes proof of vulnerability, affected versions, and exploitation vectors.

Description

Sports Accelerator Suite 2.0 - 'news_id' SQL Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/14645

This advisory details a SQL injection vulnerability in Sports Accelerator Suite v2.0, where the 'news_id' parameter in 'show_news.php' fails to sanitize user input, allowing attackers to execute arbitrary SQL queries. The document includes proof of vulnerability, affected versions, and exploitation vectors.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Sports Accelerator Suite v2.0
No auth needed
Prerequisites: Access to the vulnerable endpoint · Basic knowledge of SQL injection techniques
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026