EIP-2026-113467

PRE-CVE

Woltlab Burning Board Userlocator 2.5 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113467. PoCs published by Easy Laster.

AI-analyzed exploit summary This Ruby script exploits a SQL injection vulnerability in Woltlab Burning Board Userlocator V2.5 by injecting crafted SQL queries into the 'x' parameter of 'locator.php'. It extracts user credentials (userid, username, password, and email) from the 'bb1_users' table by leveraging a UNION-based SQL injection technique.

Description

Woltlab Burning Board Userlocator 2.5 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Easy Laster · rubywebappsphp
https://www.exploit-db.com/exploits/15465

This Ruby script exploits a SQL injection vulnerability in Woltlab Burning Board Userlocator V2.5 by injecting crafted SQL queries into the 'x' parameter of 'locator.php'. It extracts user credentials (userid, username, password, and email) from the 'bb1_users' table by leveraging a UNION-based SQL injection technique.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Woltlab Burning Board Userlocator V2.5
No auth needed
Prerequisites: Target host running Woltlab Burning Board Userlocator V2.5 · Network access to the target host
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026