EIP-2026-100209
PRE-CVECm3 CMS - 'search.asp' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100209. PoCs published by Crim3R.
AI-analyzed exploit summary The provided code demonstrates multiple XSS vulnerabilities in Cm3 CMS by injecting arbitrary JavaScript via unsanitized input parameters in search functionality. The PoC includes specific URLs with payloads that trigger script execution in the context of the affected site.
Description
Cm3 CMS - 'search.asp' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The provided code demonstrates multiple XSS vulnerabilities in Cm3 CMS by injecting arbitrary JavaScript via unsanitized input parameters in search functionality. The PoC includes specific URLs with payloads that trigger script execution in the context of the affected site.