EIP-2026-114608
PRE-CVEZenPhoto 1.4.0.3 - x-forwarded-for HTTP Header Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114608. PoCs published by Saif.
AI-analyzed exploit summary The exploit describes a persistent XSS vulnerability in ZenPhoto 1.4.0.3 due to improper sanitization of the 'x-forwarded-for' HTTP header in security logs. The PoC demonstrates how an attacker can inject malicious HTML code, which is then displayed in the admin logs.
Description
ZenPhoto 1.4.0.3 - x-forwarded-for HTTP Header Persistent Cross-Site Scripting
Exploits (1)
The exploit describes a persistent XSS vulnerability in ZenPhoto 1.4.0.3 due to improper sanitization of the 'x-forwarded-for' HTTP header in security logs. The PoC demonstrates how an attacker can inject malicious HTML code, which is then displayed in the admin logs.