EIP-2026-110475
PRE-CVEParallels H-Sphere 3.0/3.1 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-110475. PoCs published by t0fx.
AI-analyzed exploit summary The provided text describes multiple cross-site scripting (XSS) vulnerabilities in H-Sphere due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.
Description
Parallels H-Sphere 3.0/3.1 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by t0fx · textwebappsphp
https://www.exploit-db.com/exploits/32396
The provided text describes multiple cross-site scripting (XSS) vulnerabilities in H-Sphere due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target:
H-Sphere 3.0.0 Patch 9 and 3.1 Patch 1
No auth needed
Prerequisites:
Access to the vulnerable H-Sphere login page
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026