EIP-2026-100191
PRE-CVECartWIZ 1.10 - 'searchresults.asp' Name Argument Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100191. PoCs published by Dcrab.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in CartWIZ by injecting a malicious script via the 'name' parameter in a search query. The payload executes arbitrary JavaScript in the context of the victim's browser, potentially stealing cookies or performing other client-side attacks.
Description
CartWIZ 1.10 - 'searchresults.asp' Name Argument Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in CartWIZ by injecting a malicious script via the 'name' parameter in a search query. The payload executes arbitrary JavaScript in the context of the victim's browser, potentially stealing cookies or performing other client-side attacks.