EIP-2026-100226
PRE-CVECommunity Server 2007/2008 - 'TagSelector.aspx' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100226. PoCs published by PontoSec.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Community Server 2007 and 2008, where insufficient sanitization of user-supplied input in the 'TagEditor' parameter allows arbitrary script execution. The writeup includes a proof-of-concept URL demonstrating the vulnerability.
Description
Community Server 2007/2008 - 'TagSelector.aspx' Cross-Site Scripting
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in Community Server 2007 and 2008, where insufficient sanitization of user-supplied input in the 'TagEditor' parameter allows arbitrary script execution. The writeup includes a proof-of-concept URL demonstrating the vulnerability.