EIP-2026-112328
PRE-CVESoftDirec 1.05 - 'delete_confirm.php' Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112328. PoCs published by indoushka.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in SoftDirec 1.05 by injecting malicious JavaScript via the 'id' parameter in a crafted URL. The payload bypasses basic sanitization using mixed case and encoding to execute arbitrary script code in the context of the affected site.
Description
SoftDirec 1.05 - 'delete_confirm.php' Cross-Site Scripting
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in SoftDirec 1.05 by injecting malicious JavaScript via the 'id' parameter in a crafted URL. The payload bypasses basic sanitization using mixed case and encoding to execute arbitrary script code in the context of the affected site.