EIP-2026-111108
PRE-CVEphpLDAPadmin 1.2.0.5-2 - 'server_id' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111108. PoCs published by andsarmiento.
AI-analyzed exploit summary The exploit demonstrates a cross-site scripting (XSS) vulnerability in phpLDAPadmin by injecting malicious JavaScript via the 'server_id' parameter in 'cmd.php' and 'index.php'. The vulnerability arises due to insufficient input sanitization, allowing arbitrary script execution in the context of the affected site.
Description
phpLDAPadmin 1.2.0.5-2 - 'server_id' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a cross-site scripting (XSS) vulnerability in phpLDAPadmin by injecting malicious JavaScript via the 'server_id' parameter in 'cmd.php' and 'index.php'. The vulnerability arises due to insufficient input sanitization, allowing arbitrary script execution in the context of the affected site.