EIP-2026-112554

PRE-CVE

Takas Classified 1.1 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112554. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Takas Classified v1.1 by providing multiple parameterized URLs that can be manipulated to execute arbitrary SQL queries. The attack vectors are straightforward and target the 'subcatid', 'catid', 'locid', 'areaid', 'type', and 'post' parameters.

Description

Takas Classified 1.1 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/41295

The exploit demonstrates SQL injection vulnerabilities in Takas Classified v1.1 by providing multiple parameterized URLs that can be manipulated to execute arbitrary SQL queries. The attack vectors are straightforward and target the 'subcatid', 'catid', 'locid', 'areaid', 'type', and 'post' parameters.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Takas Classified – Codeigniter PHP Classified Ad Script v1.1
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026