EIP-2026-113407
PRE-CVEWHMCompleteSolution (WHMCS) - 'boleto_bb.php' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113407. PoCs published by dex.
AI-analyzed exploit summary This script checks for the presence of register globals in a WHMCS installation, which is a prerequisite for exploiting an SQL injection vulnerability. It does not perform the actual SQL injection but verifies the environment.
Description
WHMCompleteSolution (WHMCS) - 'boleto_bb.php' SQL Injection
Exploits (1)
exploitdb
SCANNER
VERIFIED
by dex · pythonwebappsphp
https://www.exploit-db.com/exploits/37331
This script checks for the presence of register globals in a WHMCS installation, which is a prerequisite for exploiting an SQL injection vulnerability. It does not perform the actual SQL injection but verifies the environment.
Classification
Scanner 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
WHMCS (WHM Complete Solution) v4.5.1
No auth needed
Prerequisites:
Register globals enabled on the target server
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026