EIP-2026-109323
PRE-CVEManx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager_OLD/ajax_get_file_listing.php' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109323. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates XSS and directory traversal vulnerabilities in Manx 1.0.1 by injecting malicious scripts into URL parameters. The PoC includes specific payloads targeting the 'limit' and 'search_folder' parameters in the ajaxfilemanager_old component.
Description
Manx 1.0.1 - '/admin/tiny_mce/plugins/ajaxfilemanager_OLD/ajax_get_file_listing.php' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates XSS and directory traversal vulnerabilities in Manx 1.0.1 by injecting malicious scripts into URL parameters. The PoC includes specific payloads targeting the 'limit' and 'search_folder' parameters in the ajaxfilemanager_old component.