EIP-2026-112846
PRE-CVEUBBCentral UBB.Threads 6.2.x < 6.3x - One Char Brute Force
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112846. PoCs published by RusH.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in UBB.Threads 6.2.* to 6.3.* by brute-forcing user credentials (login name and password hash) via a time-based blind SQLi technique. It leverages the 'like' parameter in showmembers.php to extract data character-by-character.
Description
UBBCentral UBB.Threads 6.2.x < 6.3x - One Char Brute Force
Exploits (1)
This Perl script exploits a SQL injection vulnerability in UBB.Threads 6.2.* to 6.3.* by brute-forcing user credentials (login name and password hash) via a time-based blind SQLi technique. It leverages the 'like' parameter in showmembers.php to extract data character-by-character.