EIP-2026-111207
PRE-CVEPHPShop CMS 3.4 - Multiple Cross-Site Scripting / SQL Injections
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111207. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in PHPShop CMS 3.4 by providing crafted URLs that manipulate input parameters to trigger these issues. The SQLi examples use boolean-based techniques, while the XSS examples inject JavaScript to steal cookies.
Description
PHPShop CMS 3.4 - Multiple Cross-Site Scripting / SQL Injections
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in PHPShop CMS 3.4 by providing crafted URLs that manipulate input parameters to trigger these issues. The SQLi examples use boolean-based techniques, while the XSS examples inject JavaScript to steal cookies.