EIP-2026-113005
PRE-CVEvBulletin 4.1.12 - 'blog_plugin_useradmin.php' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113005. PoCs published by Am!r.
AI-analyzed exploit summary The code describes an SQL injection vulnerability in vBulletin 4.1.12 due to insufficient sanitization of user-supplied data in the 'u' parameter of the 'blog_plugin_useradmin.php' script. The vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.
Description
vBulletin 4.1.12 - 'blog_plugin_useradmin.php' SQL Injection
Exploits (1)
The code describes an SQL injection vulnerability in vBulletin 4.1.12 due to insufficient sanitization of user-supplied data in the 'u' parameter of the 'blog_plugin_useradmin.php' script. The vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.