EIP-2026-113007
PRE-CVEvBulletin 4.x Verify Email Before Registration Plugin - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113007. PoCs published by Dave.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in the vBulletin Verify Email Before Registration plugin, specifically in the register_form_complete hook. The PoC shows how an attacker can inject a UNION-based SQL query to extract user credentials (username, password, salt) from the database.
Description
vBulletin 4.x Verify Email Before Registration Plugin - SQL Injection
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in the vBulletin Verify Email Before Registration plugin, specifically in the register_form_complete hook. The PoC shows how an attacker can inject a UNION-based SQL query to extract user credentials (username, password, salt) from the database.