EIP-2026-119304
PRE-CVEXAMPP 1.7.7 - 'PHP_SELF' Multiple Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119304. PoCs published by Gjoko Krstic.
AI-analyzed exploit summary The provided code demonstrates multiple XSS vulnerabilities in XAMPP 1.7.7 for Windows by injecting script tags into URLs targeting specific endpoints. These endpoints fail to sanitize user-supplied input, allowing arbitrary JavaScript execution in the context of the affected site.
Description
XAMPP 1.7.7 - 'PHP_SELF' Multiple Cross-Site Scripting Vulnerabilities
Exploits (1)
The provided code demonstrates multiple XSS vulnerabilities in XAMPP 1.7.7 for Windows by injecting script tags into URLs targeting specific endpoints. These endpoints fail to sanitize user-supplied input, allowing arbitrary JavaScript execution in the context of the affected site.