Computer Security
[EN] securityvulns.ru
no-pyccku



Oracle Dynamic Monitoring Services crossite scripting
Published:22.03.2007
Source:BUGTRAQ
SecurityVulns ID:7439
Type:remote
Level:5/10
Description:Crossite scripting with /servlet/Spy.
Affected:ORACLE : Oracle 10g
CVE:CVE-2007-1609 (Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.)
Original documentdocumentSea Shark, Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy (22.03.2007)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru