EIP-2026-100938
PRE-CVEWWWThread 5.0.8 Pro - 'showflat.pl' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100938. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in WWWThread by injecting arbitrary script code via the 'view' parameter in a crafted URL. The vulnerability arises due to insufficient input sanitization, allowing attackers to execute malicious scripts in the context of the affected site.
Description
WWWThread 5.0.8 Pro - 'showflat.pl' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in WWWThread by injecting arbitrary script code via the 'view' parameter in a crafted URL. The vulnerability arises due to insufficient input sanitization, allowing attackers to execute malicious scripts in the context of the affected site.