Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-2504. PoCs published by 43zsec.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Matrix42 Service Store by injecting a malicious script via the URL parameter. The PoC uses a simple alert to display the user's cookies, confirming the vulnerability.
Description
Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Matrix42 Service Store by injecting a malicious script via the URL parameter. The PoC uses a simple alert to display the user's cookies, confirming the vulnerability.