CVE-2011-0836
Oracle JD Edwards EnterpriseOne <8.98.4.1 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2011-0836. PoCs published by Juan Manuel Garcia.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script into the RENDER_MAFLET parameter. The payload is delivered via a crafted GET request, which executes arbitrary JavaScript in the context of the affected site.
Description
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.
Exploits (5)
This exploit demonstrates a reflected XSS vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script into the RENDER_MAFLET parameter. The payload is delivered via a crafted GET request, which executes arbitrary JavaScript in the context of the affected site.
The exploit demonstrates a reflected XSS vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script into the 'jdemafjasLinkTarget' parameter. The crafted URL triggers an alert popup, confirming the vulnerability.
This exploit demonstrates a reflected XSS vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script via the 'e1.namespace' parameter in a GET request. The payload is URL-encoded and triggers an alert popup when executed in a vulnerable application.
The exploit demonstrates a cross-site scripting (XSS) vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script into the 'e1.namespace' parameter. The provided HTTP request shows the payload being delivered via a POST request, which executes arbitrary JavaScript in the context of the affected site.
This exploit demonstrates a reflected XSS vulnerability in Oracle JD Edwards EnterpriseOne by injecting a malicious script into the 'jdeowpBackButtonProtect' parameter. The payload is URL-encoded and triggers an alert dialog when executed in the context of the affected site.