|
|
| |
| Oracle Portal is commonly used with Oracle Web Cache, which caches the most common used URLs. Due to this problem a malicious user can alter the content that the server will catch. This can be used in attack to rogue cookies, usernames and passwords, etc. |
| |
Credit:
The information has been provided by putosoft softputo.
|
| |
Vulnerable Systems:
* Oracle Portal 10g
Sample:
http://<target>/webapp/jsp/calendar.jsp?enc=iso-8859-1%0d%0a Content-length=12%0d%0a%0d%0a%3Cscript%3Ealert('hi')%3C/script%3E
|
|
|
|
|
|
|
|