EIP-2026-112783

PRE-CVE

Traq 2.2 - Multiple SQL Injections / Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112783. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Traq 2.2 due to insufficient input sanitization. It includes specific payloads for various parameters in different scripts, showing how an attacker could execute arbitrary SQL queries or JavaScript code.

Description

Traq 2.2 - Multiple SQL Injections / Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36175

The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Traq 2.2 due to insufficient input sanitization. It includes specific payloads for various parameters in different scripts, showing how an attacker could execute arbitrary SQL queries or JavaScript code.

Classification
Working Poc 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: Traq 2.2
No auth needed
Prerequisites: register_globals enabled for XSS exploitation
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026