EIP-2026-113003
PRE-CVEvBulletin 4.0.x 4.1.3 - 'messagegroupid' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113003. PoCs published by fb1h2s.
AI-analyzed exploit summary This is a technical writeup detailing an SQL injection vulnerability in vBulletin 4.x.x to 4.1.3, specifically in the 'messagegroupid' parameter. The vulnerability arises due to improper input validation in the file '/vbforum/search/type/socialgroupmessage.php' at line 388, allowing attackers to inject malicious SQL queries.
Description
vBulletin 4.0.x 4.1.3 - 'messagegroupid' SQL Injection
Exploits (1)
This is a technical writeup detailing an SQL injection vulnerability in vBulletin 4.x.x to 4.1.3, specifically in the 'messagegroupid' parameter. The vulnerability arises due to improper input validation in the file '/vbforum/search/type/socialgroupmessage.php' at line 388, allowing attackers to inject malicious SQL queries.