EIP-2026-109048
PRE-CVEKubeLabs PHPDug 2.0 - 'upcoming.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109048. PoCs published by indoushka.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in KubeLabs PHPDug 2.0.0 by injecting a malicious script via the 'id' parameter in the 'upcoming.php' page. The payload bypasses basic sanitization using mixed case and encoding to execute arbitrary JavaScript in the victim's browser.
Description
KubeLabs PHPDug 2.0 - 'upcoming.php' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in KubeLabs PHPDug 2.0.0 by injecting a malicious script via the 'id' parameter in the 'upcoming.php' page. The payload bypasses basic sanitization using mixed case and encoding to execute arbitrary JavaScript in the victim's browser.