Vulnerabilities > CVE-2005-0873 - Remote Cross-Site Scripting vulnerability in Oracle 10G Reports Server 9.0.4.3.3
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Oracle Reports Server 10g Multiple Remote Cross-Site Scripting Vulnerabilities. CVE-2005-0873. Webapps exploit for jsp platform |
id | EDB-ID:25269 |
last seen | 2016-02-03 |
modified | 2005-03-24 |
published | 2005-03-24 |
reporter | Paolo |
source | https://www.exploit-db.com/download/25269/ |
title | Oracle Reports Server 10g Multiple Remote Cross-Site Scripting Vulnerabilities |
Nessus
NASL family | Databases |
NASL id | ORACLE_REPORT_SERVER_XSS.NASL |
description | The remote host is running Oracle Report Server, a reporting application. The remote version of this software contains to a cross-site scripting vulnerability that may allow an attacker to use the remote host to perform a cross-site scripting attack. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17614 |
published | 2005-03-24 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17614 |
title | Oracle Reports Server test.jsp Multiple Parameter XSS |
code |
|
Saint
bid | 15134 |
description | Oracle Security Component sys.pbsde buffer overflow |
id | database_oracle_version |
osvdb | 20612 |
title | oracle_security_pbsde |
type | remote |
References
- http://marc.info/?l=bugtraq&m=111168323804203&w=2
- http://secunia.com/advisories/17250
- http://www.kb.cert.org/vuls/id/210524
- http://www.oracle.com/technetwork/topics/security/cpuoct2005-090497.html
- http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html
- http://www.securityfocus.com/bid/12892
- http://www.securityfocus.com/bid/15134
- http://www.us-cert.gov/cas/techalerts/TA05-292A.html