EIP-2026-108952
PRE-CVEK2News Management 1.3 - 'Ratings.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108952. PoCs published by meto5757.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in k2News Management due to insufficient sanitization of user-supplied input. The PoC shows how an attacker can inject malicious JavaScript code via the 'errcode' parameter to steal cookie-based authentication credentials.
Description
K2News Management 1.3 - 'Ratings.php' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in k2News Management due to insufficient sanitization of user-supplied input. The PoC shows how an attacker can inject malicious JavaScript code via the 'errcode' parameter to steal cookie-based authentication credentials.