EIP-2026-119178
PRE-CVESurgeFTP 2.x - 'surgeftpmgr.cgi' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119178. PoCs published by indoushka.
AI-analyzed exploit summary The exploit demonstrates multiple XSS vulnerabilities in SurgeFTP 2.3a6 by injecting malicious scripts via unsanitized parameters in the `surgeftpmgr.cgi` endpoint. The PoC includes crafted URLs with embedded JavaScript payloads that execute arbitrary code in the context of the administrator's browser session.
Description
SurgeFTP 2.x - 'surgeftpmgr.cgi' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The exploit demonstrates multiple XSS vulnerabilities in SurgeFTP 2.3a6 by injecting malicious scripts via unsanitized parameters in the `surgeftpmgr.cgi` endpoint. The PoC includes crafted URLs with embedded JavaScript payloads that execute arbitrary code in the context of the administrator's browser session.