EIP-2026-100857
PRE-CVEMetaDot Portal Server 5.6.x - 'userchannel.pl?op' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100857. PoCs published by JeiAr.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in MetaDot Portal Server by injecting an iframe via the 'op' parameter in the userchannel.pl script. The lack of input validation allows arbitrary HTML/JS execution in the context of the victim's session.
Description
MetaDot Portal Server 5.6.x - 'userchannel.pl?op' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in MetaDot Portal Server by injecting an iframe via the 'op' parameter in the userchannel.pl script. The lack of input validation allows arbitrary HTML/JS execution in the context of the victim's session.