Vulnerabilities > CVE-2001-0126 - Unspecified vulnerability in Oracle Oracle8I 8.1.7

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
oracle
nessus

Summary

Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

Nessus

NASL familyDatabases
NASL idORACLE_XSQL.NASL
descriptionThe Oracle XSQL Servlet allows arbitrary Java code to be executed by an attacker by supplying the URL of a malicious XSLT stylesheet when making a request to an XSQL page.
last seen2020-06-01
modified2020-06-02
plugin id10594
published2001-01-22
reporterThis script is Copyright (C) 2001-2018 Matt Moore
sourcehttps://www.tenable.com/plugins/nessus/10594
titleOracle Application Server XSQL Stylesheet Arbitrary Java Code Execution