EIP-2026-107765
PRE-CVEIG Shop 1.4 - 'Change_Pass.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107765. PoCs published by SnipEr.X.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in iG Shop version 1.4, where user-supplied input is not properly sanitized. The example demonstrates how an attacker could inject arbitrary script code into the 'id' parameter of the 'change_pass.php' page.
Description
IG Shop 1.4 - 'Change_Pass.php' Cross-Site Scripting
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in iG Shop version 1.4, where user-supplied input is not properly sanitized. The example demonstrates how an attacker could inject arbitrary script code into the 'id' parameter of the 'change_pass.php' page.