|
Red-Database-Security GmbH ist Spezialist für Oracle SecurityProdukteRepscan 2.5 Hedgehog Enterprise Checkpwd (free)
Dienstleistungen
Informationen
Neuigkeiten/Termine
Firma
|
Append file in Oracle Webcache 9i
Details It is possible to corrupt any file of an Oracle Application Server installation by appending garbage to the file (e.g. httpd.conf). This issue can be combined with cross site scripting vulnerabilities in the webcache administrator application. Patch Information Oracle fixed this issue with informing me or their customers. Testcase http://server01:4000/webcacheadmin?SCREEN_ID=CGA.CacheDump&ACTION=Submit& index=1&cache_dump_file=/opt/ORACLE/ias/9.0.2/Apache/Apache/conf/httpd.conf History 23-sep-2003 Oracle was secalert informed 23-sep-2003 Bug confirmed 26-apr-2005 Red-Database-Security published this advisory 11-may-2005 CAN added © 2005 by Red-Database-Security GmbH - last update 03-nov-2005 |
Oracle Webcache |