Various Cross-Site-Scripting Vulnerabilities in Oracle Reports
24 Oct. 2006
Summary
The Oracle Reports parameters showenv [REP01], parsequery [REP01], cellwrapper [REP02] and delimiter [REP02] are vulnerable against Cross-Site-Scripting.
Affected Products:
* Internet Application Server
* Oracle Application Server
* Oracle Developer Suite
Patch Information:
Apply Oracle Critical Patch Update October 2006 (CPU July 2006).
History:
28-aug-2003 Oracle secalert was informed
29-aug-2003 Bug confirmed
17-oct-2006 Oracle published CPU October 2006
18-oct-2006 Red-Database-Security published this advisory