Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-100845. PoCs published by Jose Carlos de Arriba.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in LISTSERV 16 by injecting a malicious script via the SHOWTPL parameter in the WA.EXE endpoint. The payload executes arbitrary JavaScript in the context of the affected site, potentially leading to cookie theft or other client-side attacks.
Description
LISTSERV 16 - 'SHOWTPL' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in LISTSERV 16 by injecting a malicious script via the SHOWTPL parameter in the WA.EXE endpoint. The payload executes arbitrary JavaScript in the context of the affected site, potentially leading to cookie theft or other client-side attacks.