EIP-2026-110391
PRE-CVEosCSS 2.1 - Multiple Cross-Site Scripting / Local File Inclusions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110391. PoCs published by AutoSec Tools.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability and multiple local file inclusion (LFI) vulnerabilities in osCSS 2.1.0 RC12. The XSS payload injects arbitrary JavaScript, while the LFI payloads traverse directories to access sensitive files like `win.ini`.
Description
osCSS 2.1 - Multiple Cross-Site Scripting / Local File Inclusions
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability and multiple local file inclusion (LFI) vulnerabilities in osCSS 2.1.0 RC12. The XSS payload injects arbitrary JavaScript, while the LFI payloads traverse directories to access sensitive files like `win.ini`.