EIP-2026-109620
PRE-CVEMTP Image Gallery 1.0 - 'edit_photos.php?title' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109620. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in MTP Image Gallery 1.0 by injecting malicious scripts into the 'title' parameter via POST requests to 'edit_photos.php' and 'add_cat.php'. The PoC includes HTML forms that submit payloads to trigger the vulnerability.
Description
MTP Image Gallery 1.0 - 'edit_photos.php?title' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in MTP Image Gallery 1.0 by injecting malicious scripts into the 'title' parameter via POST requests to 'edit_photos.php' and 'add_cat.php'. The PoC includes HTML forms that submit payloads to trigger the vulnerability.