PT-2000-1152 · Oracle · Oracle Web Listener
Publicado
2000-03-15
·
Atualizado
2008-09-10
·
CVE-2000-0169
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle web listener (affected versions not specified)
Description
The issue allows remote attackers to execute commands via a malformed URL that includes '?&'. This can be achieved by accessing specific API endpoints, although the exact endpoints are not specified. The general idea is that by manipulating the URL with certain characters, an attacker can bypass normal security restrictions and execute unauthorized commands on the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Web Listener