EIP-2026-113036
PRE-CVEvCard 2.9 - Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113036. PoCs published by black-code.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in vCard, where user-supplied input is not properly sanitized in the 'page' parameter of 'toprated.php' and 'newcards.php'. The vulnerability allows arbitrary script execution in the context of the affected site.
Description
vCard 2.9 - Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in vCard, where user-supplied input is not properly sanitized in the 'page' parameter of 'toprated.php' and 'newcards.php'. The vulnerability allows arbitrary script execution in the context of the affected site.