Oracle Configurator Text Features User-Embedded Scripting Vulnerability
BID:4430
Info
Oracle Configurator Text Features User-Embedded Scripting Vulnerability
| Bugtraq ID: | 4430 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2002 12:00AM |
| Updated: | Apr 01 2002 12:00AM |
| Credit: | Published in Oracle Security Alert #31. |
| Vulnerable: |
Oracle Configurator 11.0 i |
| Not Vulnerable: | |
Discussion
Oracle Configurator Text Features User-Embedded Scripting Vulnerability
An issue has been discovered in Oracle Configurator, which may allow users to execute script as the web host.
Oracle fails to properly filter malicious HTML tags and script from text input boxes, as a result, a host using Text Features and the DHTML user interface are subject to this issue. Script code submitted by the end user will execute within the context of the vulnerable page.
An issue has been discovered in Oracle Configurator, which may allow users to execute script as the web host.
Oracle fails to properly filter malicious HTML tags and script from text input boxes, as a result, a host using Text Features and the DHTML user interface are subject to this issue. Script code submitted by the end user will execute within the context of the vulnerable page.
Exploit / POC
Oracle Configurator Text Features User-Embedded Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle Configurator Text Features User-Embedded Scripting Vulnerability
Solution:
This issue is resolved in CZ patchset H, and in builds 17.32 and 16.53. Please contact Oracle support for further information on obtaining the patch.
Solution:
This issue is resolved in CZ patchset H, and in builds 17.32 and 16.53. Please contact Oracle support for further information on obtaining the patch.
References
Oracle Configurator Text Features User-Embedded Scripting Vulnerability
References:
References:
- Oracle Security Alert #31 (Oracle )