Resource Name:

Oracle XSQL servlet and xml-stylesheet allows code execution on server

 

Resource Desc:

Oracle version 8.1.7 could allow a remote attacker to execute Java on a Web server, due to a vulnerability in the XSQL servlet. The Oracle XSQL servlet allows Java to be executed by external XSLT stylesheets regardless of where they reside. A remote attacker could exploit this vulnerability to compromise the Web server.

 

Resource URL:

http://xforce.iss.net/xforce/xfdb/5905

 

Rating: 0.00

 

# Times Viewed: 583

 

Reviews