EIP-2026-106972
PRE-CVEExpressionEngine 1.2.1 - HTTP Response Splitting / Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106972. PoCs published by MustLive.
AI-analyzed exploit summary This exploit demonstrates an HTTP response splitting and XSS vulnerability in ExpressionEngine by injecting malicious headers and script tags via the URL parameter. It leverages improper input sanitization to execute arbitrary JavaScript in the context of a victim's browser.
Description
ExpressionEngine 1.2.1 - HTTP Response Splitting / Cross-Site Scripting
Exploits (1)
This exploit demonstrates an HTTP response splitting and XSS vulnerability in ExpressionEngine by injecting malicious headers and script tags via the URL parameter. It leverages improper input sanitization to execute arbitrary JavaScript in the context of a victim's browser.