EIP-2026-113467
PRE-CVEWoltlab Burning Board Userlocator 2.5 - SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113467. PoCs published by Easy Laster.
AI-analyzed exploit summary This Ruby script exploits a SQL injection vulnerability in Woltlab Burning Board Userlocator V2.5 by injecting crafted SQL queries into the 'x' parameter of 'locator.php'. It extracts user credentials (userid, username, password, and email) from the 'bb1_users' table by leveraging a UNION-based SQL injection technique.
Description
Woltlab Burning Board Userlocator 2.5 - SQL Injection
Exploits (1)
This Ruby script exploits a SQL injection vulnerability in Woltlab Burning Board Userlocator V2.5 by injecting crafted SQL queries into the 'x' parameter of 'locator.php'. It extracts user credentials (userid, username, password, and email) from the 'bb1_users' table by leveraging a UNION-based SQL injection technique.