Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-103906. PoCs published by Kacper Szczesniak.
AI-analyzed exploit summary This exploit leverages ARP and DNS spoofing to intercept traffic and inject malicious JavaScript into HTTP responses, triggering arbitrary code execution via a crafted HTML event in Gadu-Gadu 10.5. The attack requires man-in-the-middle positioning and relies on social engineering to execute local binaries.
Description
Gadu-Gadu 10.5 - Remote Code Execution
Exploits (1)
This exploit leverages ARP and DNS spoofing to intercept traffic and inject malicious JavaScript into HTTP responses, triggering arbitrary code execution via a crafted HTML event in Gadu-Gadu 10.5. The attack requires man-in-the-middle positioning and relies on social engineering to execute local binaries.