Reported January 24, 2004 by Rafel Ivgi.
VERSIONS AFFECTED
-
Oracle HTTP Server (powered by Apache)
DESCRIPTION
Oracle HTTP Server is vulnerable to cross-site scripting. An attacker could craft a specially formed URL that could cause the code of the attacker's choice to run on the user's local system. The vulnerability might lead to manipulated Web content, stolen cookie data, or arbitrary actions under the context of the user's Web session.
VENDOR RESPONSE
The vendors are aware of the problem.
CREDIT
Discovered by Rafel Ivgi.
0 comments
Hide comments