EIP-2026-109234

PRE-CVE

Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109234. PoCs published by Lorenzo Hernandez Garcia-Hierro.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP authentication pages generated by Macromedia Dreamweaver MX PHP Authentication Suite. The vulnerability allows arbitrary HTML code execution in the browser of an unsuspecting user via a crafted URL.

Description

Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by Lorenzo Hernandez Garcia-Hierro · textwebappsphp
https://www.exploit-db.com/exploits/22986

This exploit demonstrates a cross-site scripting (XSS) vulnerability in PHP authentication pages generated by Macromedia Dreamweaver MX PHP Authentication Suite. The vulnerability allows arbitrary HTML code execution in the browser of an unsuspecting user via a crafted URL.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Macromedia Dreamweaver MX PHP Authentication Suite
No auth needed
Prerequisites: Access to the target URL with the vulnerable parameter
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026