CVE-2010-2404 | Persistent Cross Site Scripting Vulnerability in Oracle I-Recruitment - E-Business Suite Jul 13 2011 02:54AM
Aditya K Sood (0kn0ck secniche org)
Advisory: Persistent Cross Site Scripting Vulnerability in Oracle I-Recruitment File Uploading Module- E-Business Suite


Version Affected -, 12.0.6, 12.1.3

About: Oracle I-Recruitment Suite
Oracle iRecruitment is a web based full-cycle recruiting solution that
gives managers, recruiters and candidates the ability to manage every
phase of finding, recruiting, hiring, and tracking new employees. It is a
part of Oracle E-business suite.

A persistent cross site scripting vulnerability exists in the I-Recruitment
portal. The account information page allows the user to upload his resume in
Microsoft Word document. An attacker can construct a malicious MSWord file to
conduct XSS attack by setting XSS payload in hyperlinks in order to bypass
conversion filters.

For attack details , Refer to the following paper:

The vulnerability was disclosed to Oracle in January 2009 and is patched
in October 2010 CPU release.

Aditya K Sood of SecNiche Security

adi_ks [at] secniche.org

The information in the advisory is believed to be accurate at the time of
publishing based on currently available information. Use of the
information constitutes acceptance for use in an AS IS condition. There is
no representation or warranties, either express or implied by or with
respect to anything.

[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus