EIP-2026-104032
PRE-CVEOracle E-Business Suite Financials 12 - 'jtfwcpnt.jsp' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104032. PoCs published by Joxean Koret.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite Financials by crafting malicious SQL queries via the 'query' parameter in 'jtfwcpnt.jsp'. The PoC shows how an attacker can execute arbitrary SQL commands, such as granting DBA privileges or deleting records, without authentication.
Description
Oracle E-Business Suite Financials 12 - 'jtfwcpnt.jsp' SQL Injection
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite Financials by crafting malicious SQL queries via the 'query' parameter in 'jtfwcpnt.jsp'. The PoC shows how an attacker can execute arbitrary SQL commands, such as granting DBA privileges or deleting records, without authentication.