EIP-2026-119447

PRE-CVE

TripSpark VEO Transportation - Blind SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119447. PoCs published by Sedric Louissaint.

AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in TripSpark VEO Transportation software via the 'editOEN' parameter. The PoC uses a crafted POST request to trigger a DNS/HTTP request via 'xp_dirtree', potentially capturing NetNTLMv2 hashes.

Description

TripSpark VEO Transportation - Blind SQL Injection

Exploits (1)

exploitdb WORKING POC
by Sedric Louissaint · textwebappswindows
https://www.exploit-db.com/exploits/50161

This exploit demonstrates a blind SQL injection vulnerability in TripSpark VEO Transportation software via the 'editOEN' parameter. The PoC uses a crafted POST request to trigger a DNS/HTTP request via 'xp_dirtree', potentially capturing NetNTLMv2 hashes.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: TripSpark VEO Transportation (NovusEDU-2.2.x-XP_BB-20201123-184084 / VEO--20201123-184084)
No auth needed
Prerequisites: Access to the vulnerable web application · Outbound SMB/DNS connectivity to capture hashes
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026