Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-112384. PoCs published by Adam Baldwin.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Spiceworks by injecting a malicious script via the 'query' parameter in the search functionality. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.
Description
SpiceWorks - 'query' Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Spiceworks by injecting a malicious script via the 'query' parameter in the search functionality. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies or performing other malicious actions.