EIP-2026-112840

PRE-CVE

u-Auctions - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112840. PoCs published by *Don*.

AI-analyzed exploit summary The exploit demonstrates a blind SQL injection in u-Auctions via the 'category' parameter in adsearch.php and HTTP parameter pollution in feedback.php. The SQLi payload uses time-based techniques (sleep) to confirm vulnerability, while the HPP attack manipulates the 'id' parameter to override application behavior.

Description

u-Auctions - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by *Don* · textwebappsphp
https://www.exploit-db.com/exploits/36641

The exploit demonstrates a blind SQL injection in u-Auctions via the 'category' parameter in adsearch.php and HTTP parameter pollution in feedback.php. The SQLi payload uses time-based techniques (sleep) to confirm vulnerability, while the HPP attack manipulates the 'id' parameter to override application behavior.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: u-Auctions (all versions)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026