EIP-2026-113182

PRE-CVE

Water Billing System 1.0 - 'id' SQL Injection (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113182. PoCs published by Mehmet Kelepçe.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the 'id' parameter of two PHP files (edituser.php and viewbill.php) in the Water Billing System 1.0. The PoC includes HTTP requests with malicious SQL payloads to extract database version information.

Description

Water Billing System 1.0 - 'id' SQL Injection (Authenticated)

Exploits (1)

exploitdb WORKING POC
by Mehmet Kelepçe · textwebappsphp
https://www.exploit-db.com/exploits/49048

This exploit demonstrates SQL injection vulnerabilities in the 'id' parameter of two PHP files (edituser.php and viewbill.php) in the Water Billing System 1.0. The PoC includes HTTP requests with malicious SQL payloads to extract database version information.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Water Billing System 1.0
Auth required
Prerequisites: Authenticated session (PHPSESSID cookie) · Access to vulnerable endpoints
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026