EIP-2026-113182
PRE-CVEWater Billing System 1.0 - 'id' SQL Injection (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113182. PoCs published by Mehmet Kelepçe.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the 'id' parameter of two PHP files (edituser.php and viewbill.php) in the Water Billing System 1.0. The PoC includes HTTP requests with malicious SQL payloads to extract database version information.
Description
Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
Exploits (1)
exploitdb
WORKING POC
by Mehmet Kelepçe · textwebappsphp
https://www.exploit-db.com/exploits/49048
This exploit demonstrates SQL injection vulnerabilities in the 'id' parameter of two PHP files (edituser.php and viewbill.php) in the Water Billing System 1.0. The PoC includes HTTP requests with malicious SQL payloads to extract database version information.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Water Billing System 1.0
Auth required
Prerequisites:
Authenticated session (PHPSESSID cookie) · Access to vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026