EIP-2026-106207
PRE-CVEcPanel 10.8.1/10.8.2 - OnMouseover Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106207. PoCs published by MexHackTeam.org.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in cPanel by injecting malicious JavaScript into the 'file' parameter of the 'select.html' page. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.
Description
cPanel 10.8.1/10.8.2 - OnMouseover Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in cPanel by injecting malicious JavaScript into the 'file' parameter of the 'select.html' page. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.