PT-2005-3293 · Oracle · Oracle Reports

Alexander Kornbrust

·

Publicado

2005-07-26

·

Atualizado

2016-10-18

·

CVE-2005-2379

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Reports version 9.0.2
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via several parameters, including the debug parameter to showenv, the test parameter to parsequery, or the delimiter or CELLWRAPPER parameter to rwservlet.
Recommendations For Oracle Reports version 9.0.2, consider disabling the showenv, parsequery, and rwservlet functions until a patch is available to prevent exploitation through the debug, test, delimiter, and CELLWRAPPER parameters. Restrict access to these parameters to minimize the risk of XSS attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2379

Produtos afetados

Oracle Reports