Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105327. PoCs published by Ibrahim El-Sayed.
AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities in AVA VoIP 1.5.12 by injecting malicious iframe payloads via unsanitized input parameters in agent_accounts_report.php, tariff_add.php, and routeset_set.php. The payload triggers arbitrary JavaScript execution in the context of the affected site.
Description
AVA VoIP - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates multiple reflected XSS vulnerabilities in AVA VoIP 1.5.12 by injecting malicious iframe payloads via unsanitized input parameters in agent_accounts_report.php, tariff_add.php, and routeset_set.php. The payload triggers arbitrary JavaScript execution in the context of the affected site.