EIP-2026-112997
PRE-CVEvBulletin 4.0.2 - 'update_order' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112997. PoCs published by n3tw0rk.
AI-analyzed exploit summary The writeup describes an SQL injection vulnerability in vBulletin 4.0.x due to insufficient sanitization of the 'update_order' variable in the 'force_read_thread.php' script. The proof-of-concept demonstrates how an attacker with admin access can inject malicious SQL syntax by inserting a single quote into the 'force_read_order' field.
Description
vBulletin 4.0.2 - 'update_order' SQL Injection
Exploits (1)
The writeup describes an SQL injection vulnerability in vBulletin 4.0.x due to insufficient sanitization of the 'update_order' variable in the 'force_read_thread.php' script. The proof-of-concept demonstrates how an attacker with admin access can inject malicious SQL syntax by inserting a single quote into the 'force_read_order' field.