EIP-2026-107456
PRE-CVEGollos 2.8 - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107456. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple reflected XSS vulnerabilities in Gollos 2.8 by injecting malicious scripts via the 'returnurl' and 'q' parameters in various URLs. The PoC uses simple script injection to trigger arbitrary JavaScript execution in the context of the affected site.
Description
Gollos 2.8 - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple reflected XSS vulnerabilities in Gollos 2.8 by injecting malicious scripts via the 'returnurl' and 'q' parameters in various URLs. The PoC uses simple script injection to trigger arbitrary JavaScript execution in the context of the affected site.