Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-110368. PoCs published by daandeveloper33.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in osCommerce v2.2 by directly submitting a form to change the admin password without proper authorization checks. The provided HTML form allows an attacker to reset the admin password by sending a POST request to the vulnerable endpoint.
Description
osCommerce 2.2 - Cross-Site Request Forgery
Exploits (1)
This exploit leverages an authentication bypass vulnerability in osCommerce v2.2 by directly submitting a form to change the admin password without proper authorization checks. The provided HTML form allows an attacker to reset the admin password by sending a POST request to the vulnerable endpoint.