
Exploit for CVE-2025-5878 targeting ESAPI's encodeForSQL() method with OracleCodec, enabling time-based blind SQL injection. Supports database enumeration, table/column dumping, and cookie-based authentication.
Affected: ESAPI.encoder().encodeForSQL() method and OracleCodec() class
Affected versions: 2.2.0.0-2.6.2.0
Usage: (similar to sqlmap)
usage: esapi-sqlinjection.py [-h] -u URL -c COOKIE [--dbs] [--tables] [--columns] [-D DB] [-T TABLE] [-C COLUMN] [--dump]
esapi-sqlinjection.py: error: the following arguments are required: -u/--url, -c/--cookie
Mitigation: Upgrade ESAPI library to 2.7.0.0