Oracle.HTTP.Server.XSS

description-logoDescription

This indicates a possible exploit of Cross-Site Scripting vulnerability in Oracle HTTP Server.
The vulnerability may allow an attacker to execute a malicious script in a victims browser, in the security context of the hosting site, as another user. This can be accomplished via the (1) action, (2) username, or (3) password parameters in an "isqlplus" request. It may allow the theft of cookie based authentication credentials or other attacks.

affected-products-logoAffected Products

Oracle HTTP Server 9.2 .0 and earlier versions.

Impact logoImpact

System compromise: access to authentication credentials and other cookie based information associated with a web site.

recomended-action-logoRecommended Actions

Apply appropriate patch from the vendor.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)