EIP-2026-102381
PRE-CVEJBMC Software DirectAdmin 1.403 - 'domain' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102381. PoCs published by Dawid Golak.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in DirectAdmin by injecting malicious JavaScript via the 'domain' parameter in the CMD_DOMAIN endpoint. The PoC uses an onmouseover event to trigger an alert, proving arbitrary script execution in the context of the affected site.
Description
JBMC Software DirectAdmin 1.403 - 'domain' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in DirectAdmin by injecting malicious JavaScript via the 'domain' parameter in the CMD_DOMAIN endpoint. The PoC uses an onmouseover event to trigger an alert, proving arbitrary script execution in the context of the affected site.