Computer Security
[EN] securityvulns.ru no-pyccku


Oracle Dynamic Monitoring Services crossite scripting
Published:22.03.2007
Source:
SecurityVulns ID:7439
Type:remote
Threat Level:
5/10
Description:Crossite scripting with /servlet/Spy.
Affected:ORACLE : Oracle 10g
CVE:CVE-2007-1609 (Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.)
Original documentdocumentSea Shark, Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy (22.03.2007)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod