Cross Site Scripting in Oracle HTTP Server

Reported January 24, 2004 by Rafel Ivgi.


VERSIONS AFFECTED

  • Oracle HTTP Server (powered by Apache)

DESCRIPTION

Oracle HTTP Server is vulnerable to cross-site scripting. An attacker could craft a specially formed URL that could cause the code of the attacker's choice to run on the user's local system. The vulnerability might lead to manipulated Web content, stolen cookie data, or arbitrary actions under the context of the user's Web session.

VENDOR RESPONSE

The vendors are aware of the problem.

CREDIT

Discovered by Rafel Ivgi.

TAGS: Security
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish