PT-2000-1152 · Oracle · Oracle Web Listener

Published

2000-03-15

·

Updated

2008-09-10

·

CVE-2000-0169

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle web listener (affected versions not specified)
Description The issue allows remote attackers to execute commands via a malformed URL that includes '?&'. This can be achieved by accessing specific API endpoints, although the exact endpoints are not specified. The general idea is that by manipulating the URL with certain characters, an attacker can bypass normal security restrictions and execute unauthorized commands on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0169

Affected Products

Oracle Web Listener