EIP-2026-102462
PRE-CVEBEA WebLogic 7.0/8.1 - Administration Console LoginForm.jsp Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102462. PoCs published by Team SHATTER.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in BEA WebLogic Server and WebLogic Express due to improper sanitization of user-supplied input in the 'LoginForm.jsp' script. The PoC provides URLs that inject malicious JavaScript to steal cookie-based authentication credentials.
Description
BEA WebLogic 7.0/8.1 - Administration Console LoginForm.jsp Cross-Site Scripting
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in BEA WebLogic Server and WebLogic Express due to improper sanitization of user-supplied input in the 'LoginForm.jsp' script. The PoC provides URLs that inject malicious JavaScript to steal cookie-based authentication credentials.