EIP-2026-110475

PRE-CVE

Parallels H-Sphere 3.0/3.1 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110475. PoCs published by t0fx.

AI-analyzed exploit summary The provided text describes multiple cross-site scripting (XSS) vulnerabilities in H-Sphere due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.

Description

Parallels H-Sphere 3.0/3.1 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WRITEUP VERIFIED
by t0fx · textwebappsphp
https://www.exploit-db.com/exploits/32396

The provided text describes multiple cross-site scripting (XSS) vulnerabilities in H-Sphere due to insufficient sanitization of user-supplied data. It includes example URLs demonstrating the vulnerability but lacks actual exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: H-Sphere 3.0.0 Patch 9 and 3.1 Patch 1
No auth needed
Prerequisites: Access to the vulnerable H-Sphere login page
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026