EIP-2026-101406
PRE-CVEPalm WebOS 1.0/1.1 - Email Arbitrary Script Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101406. PoCs published by Townsend Ladd Harris.
AI-analyzed exploit summary This exploit leverages an arbitrary script injection vulnerability in Palm WebOS's email application to read the /etc/passwd file and exfiltrate its contents to an attacker-controlled server via XMLHttpRequest. The vulnerability arises from insufficient input sanitization in versions prior to WebOS 1.2.
Description
Palm WebOS 1.0/1.1 - Email Arbitrary Script Injection
Exploits (1)
This exploit leverages an arbitrary script injection vulnerability in Palm WebOS's email application to read the /etc/passwd file and exfiltrate its contents to an attacker-controlled server via XMLHttpRequest. The vulnerability arises from insufficient input sanitization in versions prior to WebOS 1.2.