EIP-2026-112565
PRE-CVETaxi Booking Script 1.0 - Cross-site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112565. PoCs published by Tauco.
AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in Taxi Booking Script v1.0 by injecting malicious JavaScript into the 'name', 'uuid', and 'pickup_address' parameters. The PoC includes crafted HTTP POST requests that trigger the XSS payload, redirecting users to an external site.
Description
Taxi Booking Script 1.0 - Cross-site Scripting
Exploits (1)
The exploit demonstrates a persistent XSS vulnerability in Taxi Booking Script v1.0 by injecting malicious JavaScript into the 'name', 'uuid', and 'pickup_address' parameters. The PoC includes crafted HTTP POST requests that trigger the XSS payload, redirecting users to an external site.