BugTraq
Re: XSS in Oracle default fcgi-bin/echo Oct 13 2010 08:18PM
paul szabo sydney edu au (1 replies)
RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo Oct 13 2010 08:42PM
Thor (Hammer of God) (thor hammerofgod com) (1 replies)
>Hmm... maybe difficult to verify, since I did not post a PoC test.
>Maybe a kind Oracle admin could point me to a patched fcgi-bin/echo?
>Funny if any such existed: an admin careful to keep patches up-to-date, but
>careless in not following security recommendations to remove...
>Maybe, contact me off-list so I can provide PoC?

If you are going to give PoC code to anyone who asks for it, why not just post it? It will be made public anyway. Or you could apply the patch yourself and test on your own and communicate any vulnerabilities that my persist to Oracle first.

t

[ reply ]
RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo Oct 13 2010 08:49PM
paul szabo sydney edu au (1 replies)
RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo Oct 13 2010 09:14PM
Thor (Hammer of God) (thor hammerofgod com) (1 replies)
RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo Oct 13 2010 09:35PM
paul szabo sydney edu au (1 replies)
Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo Oct 17 2010 06:23AM
Riyaz Walikar (riyazwalikar gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus