Vulnerabilities > CVE-2009-1968 - Unspecified vulnerability in Oracle Database Server 10.1.8.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Oracle 10g Secure Enterprise Search 'search_p_groups' Parameter Cross Site Scripting Vulnerability. CVE-2009-1968. Remote exploits for multiple platform |
id | EDB-ID:33082 |
last seen | 2016-02-03 |
modified | 2009-06-14 |
published | 2009-06-14 |
reporter | Alexandr Polyakov |
source | https://www.exploit-db.com/download/33082/ |
title | Oracle 10g Secure Enterprise Search 'search_p_groups' Parameter Cross-Site Scripting Vulnerability |
Nessus
NASL family CGI abuses : XSS NASL id ORACLE_SES_SEARCH_P_GROUPS_XSS.NASL description The version of Oracle Secure Enterprise Search installed on the remote host fails to sanitize input to the last seen 2020-06-01 modified 2020-06-02 plugin id 40550 published 2009-08-11 reporter This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/40550 title Oracle Database Secure Enterprise Search search/query/search search_p_groups Parameter XSS NASL family Databases NASL id ORACLE_RDBMS_CPU_JUL_2009.NASL description The remote Oracle database server is missing the July 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components : - Advanced Replication - Auditing - Config Management - Core RDBMS - Listener - Network Foundation - Secure Enterprise Search - Upgrade - Visual Private Database last seen 2020-06-02 modified 2011-11-16 plugin id 56065 published 2011-11-16 reporter This script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/56065 title Oracle Database Multiple Vulnerabilities (July 2009 CPU)
Packetstorm
data source | https://packetstormsecurity.com/files/download/79328/DSECRG-09-025.txt |
id | PACKETSTORM:79328 |
last seen | 2016-12-05 |
published | 2009-07-17 |
reporter | Sh2kerr |
source | https://packetstormsecurity.com/files/79328/Oracle-Secure-Enterprise-Search-XSS.html |
title | Oracle Secure Enterprise Search XSS |
References
- http://archives.neohapsis.com/archives/bugtraq/2009-07/0110.html
- http://archives.neohapsis.com/archives/bugtraq/2009-07/0110.html
- http://dsecrg.com/pages/vul/show.php?id=125
- http://dsecrg.com/pages/vul/show.php?id=125
- http://osvdb.org/55892
- http://osvdb.org/55892
- http://secunia.com/advisories/35776
- http://secunia.com/advisories/35776
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.securityfocus.com/bid/35681
- http://www.securityfocus.com/bid/35681
- http://www.securitytracker.com/id?1022560
- http://www.securitytracker.com/id?1022560
- http://www.vupen.com/english/advisories/2009/1900
- http://www.vupen.com/english/advisories/2009/1900
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51754
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51754