Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-2370. PoCs published by Markot.
AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Oracle Business Process Management by injecting arbitrary JavaScript via the 'context' parameter in the 'tips.jsp' endpoint. The PoC includes example URLs that trigger script execution in the context of the affected site.
Description
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.
Exploits (1)
The exploit demonstrates a reflected XSS vulnerability in Oracle Business Process Management by injecting arbitrary JavaScript via the 'context' parameter in the 'tips.jsp' endpoint. The PoC includes example URLs that trigger script execution in the context of the affected site.