EIP-2026-112592
PRE-CVETemplate Seller Pro 3.25 - 'tempid' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112592. PoCs published by v3n0m.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in AlstraSoft Template Seller Pro 3.25 by injecting a malicious query into the 'tempid' parameter of 'fullview.php'. It extracts admin credentials (username and password hash) from the 'UserDB' table using a UNION-based attack.
Description
Template Seller Pro 3.25 - 'tempid' SQL Injection
Exploits (1)
This Perl script exploits a SQL injection vulnerability in AlstraSoft Template Seller Pro 3.25 by injecting a malicious query into the 'tempid' parameter of 'fullview.php'. It extracts admin credentials (username and password hash) from the 'UserDB' table using a UNION-based attack.