EIP-2026-100187
PRE-CVECartWIZ 1.10 - 'login.asp' Redirect Argument Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100187. PoCs published by Dcrab.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in CartWIZ by injecting a malicious script via the 'redirect' parameter in the login page URL. The script executes arbitrary JavaScript in the context of the user's browser, potentially stealing cookies or performing other malicious actions.
Description
CartWIZ 1.10 - 'login.asp' Redirect Argument Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in CartWIZ by injecting a malicious script via the 'redirect' parameter in the login page URL. The script executes arbitrary JavaScript in the context of the user's browser, potentially stealing cookies or performing other malicious actions.