Cross Site Scripting in Oracle HTTP Server

Oracle HTTP Server is vulnerable to cross-site scripting.

ITPro Today

January 26, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 24, 2004 by RafelIvgi.


VERSIONS AFFECTED

  • Oracle HTTP Server (powered byApache)

DESCRIPTION

Oracle HTTP Server isvulnerable to cross-site scripting. An attacker could craft a speciallyformed URL that could cause the code of the attacker's choice to run onthe user's local system. The vulnerability might lead to manipulatedWeb content, stolen cookie data, or arbitrary actions under the contextof the user's Web session.

VENDOR RESPONSE

Thevendors are aware of the problem.

CREDIT

Discoveredby Rafel Ivgi.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like