Oracle iSQLPlus跨站脚本漏洞

Oracle iSQLPlus跨站脚本漏洞

漏洞ID 1197631 漏洞类型 跨站脚本
发布时间 2005-10-14 更新时间 2005-10-20
图片[1]-Oracle iSQLPlus跨站脚本漏洞-安全小百科CVE编号 CVE-2005-3205
图片[2]-Oracle iSQLPlus跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200510-106
漏洞平台 N/A CVSS评分 3.5
|漏洞来源
https://cxsecurity.com/issue/WLB-2005100023
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200510-106
|漏洞详情
Oracle是一款大型的商业数据库系统,OracleiSQL*Plus是SQL*Plus的WEB界面。OracleiSQL*Plus中存在跨站脚本漏洞,起因是没有正确的验证用户输入。攻击者可以利用这个漏洞在用户浏览器中执行任意脚本代码。
|漏洞EXP
Cross-Site-Scripting Vulnerability in Oracle iSQL*Plus 
######################################################

Name                Cross-Site-Scripting Vulnerability in Oracle iSQLPlus
 Systems Affected    Oracle Database 9i Rel. 2
 Severity            Low Risk 
 Category            Cross Site Scripting (CSS/XSS)
 Vendor URL          http://www.oracle.com
 This advisory       http://www.red-database-security.com/advisory/oracle_isqlplus_css.html
 Author              Alexander Kornbrust (ak at red-database-security.com) 
 Date                7 October 2005 (V 1.00)

Details
#######
Oracle iSQL*Plus is a web interface to SQL*Plus and vulnerable against cross site scripting.

Affected Products
#################
Oracle Database 9i Release 2

Testcase 
########

1. Start iSQLPlus and login as user scott (http://myserver/isqlplus )

2. set markup HTML TABLE ><script>alert(document.cookie);</script>

3. select a table (e.g. select * from cat)

==> a window pops up

Affected systems 
################
Tested with Oracle Database 9.0.2.4.

Patch Information
#################
This bug is fixed with Critical Patch Update July 2005 (CPU July 2005). Oracle 
forgot to inform Red-Database-Security that this bug is fixed with CPU July 2005.

All already published alerts are available on the web site of Red-Database-Security GmbH
http://www.red-database-security.com/advisory/published_alerts.html

History
#######
5-nov-2003 Oracle secalert was informed

6-nov-2003 Bug confirmed

12-jul-2005 Oracle published CPU July 2005 without informing Red-Database-Security 
that this bug is already fixed.

07-oct-2005 Red-Database-Security published this advisory

&#169; 2005 by Red-Database-Security GmbH - last update 7-october-2005
|参考资料

来源:MISC
链接:http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html
来源:XF
名称:oracle-isqlplus-xss(22539)
链接:http://xforce.iss.net/xforce/xfdb/22539
来源:BID
名称:15030
链接:http://www.securityfocus.com/bid/15030
来源:MISC
链接:http://www.red-database-security.com/advisory/oracle_isqlplus_css.html
来源:SREASON
名称:63
链接:http://securityreason.com/securityalert/63
来源:SECUNIA
名称:15991
链接:http://secunia.com/advisories/15991/
来源:BUGTRAQ
名称:20051007Cross-Site-ScriptingVulnerabilityinOracleiSQL*Plus
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112870489324437&w;=2
来源:FULLDISC
名称:20051007Cross-Site-ScriptingVulnerabilityinOracleiSQL*Plus
链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0172.html

相关推荐: FreeBSD angband缓冲区溢出漏洞

FreeBSD angband缓冲区溢出漏洞 漏洞ID 1105626 漏洞类型 缓冲区溢出 发布时间 1999-12-01 更新时间 2005-05-02 CVE编号 CVE-1999-0826 CNNVD-ID CNNVD-199912-005 漏洞平台 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享