Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104080. PoCs published by noptrix.
AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in Skype versions 5.3.0.120 and prior, where user-supplied input is not properly sanitized, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The example payload demonstrates a simple XSS attack using an iframe with an onload event.
Description
Skype 5.3 - 'Mobile Phone' HTML Injection
Exploits (1)
The provided text describes an HTML injection vulnerability in Skype versions 5.3.0.120 and prior, where user-supplied input is not properly sanitized, allowing attacker-supplied HTML and script code to execute in the context of the affected browser. The example payload demonstrates a simple XSS attack using an iframe with an onload event.