Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3581. PoCs published by Alexander Polyakov.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Oracle BPEL Console by injecting a script tag into the 'processName' parameter of the 'processLog.jsp' endpoint. The vulnerability requires a valid session and can be exploited to execute arbitrary JavaScript in the context of the affected site.
Description
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in Oracle BPEL Console by injecting a script tag into the 'processName' parameter of the 'processLog.jsp' endpoint. The vulnerability requires a valid session and can be exploited to execute arbitrary JavaScript in the context of the affected site.