EIP-2026-112436
PRE-CVEStock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112436. PoCs published by Riadh Benlamine.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Stock Management System 1.0 via the 'user_id' parameter in '/stock/php_action/changePassword.php'. It includes SQLmap commands for exploitation and a CSRF/XSS chaining technique to steal session cookies.
Description
Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in Stock Management System 1.0 via the 'user_id' parameter in '/stock/php_action/changePassword.php'. It includes SQLmap commands for exploitation and a CSRF/XSS chaining technique to steal session cookies.