EIP-2026-112846

PRE-CVE

UBBCentral UBB.Threads 6.2.x < 6.3x - One Char Brute Force

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112846. PoCs published by RusH.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in UBB.Threads 6.2.* to 6.3.* by brute-forcing user credentials (login name and password hash) via a time-based blind SQLi technique. It leverages the 'like' parameter in showmembers.php to extract data character-by-character.

Description

UBBCentral UBB.Threads 6.2.x < 6.3x - One Char Brute Force

Exploits (1)

exploitdb WORKING POC VERIFIED
by RusH · perlwebappsphp
https://www.exploit-db.com/exploits/630

This Perl script exploits a SQL injection vulnerability in UBB.Threads 6.2.* to 6.3.* by brute-forcing user credentials (login name and password hash) via a time-based blind SQLi technique. It leverages the 'like' parameter in showmembers.php to extract data character-by-character.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: UBB.Threads 6.2.* - 6.3.*
No auth needed
Prerequisites: Access to the target's showmembers.php endpoint · Valid username to brute-force
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026