[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [Full-disclosure] CVE-2014-0379 - Stored Cross-site Scripting in Oracle Demantra
From:       Portcullis Advisories <advisories () portcullis-security ! com>
Date:       2014-02-28 15:46:32
Message-ID: 5310AF58.1040801 () portcullis-security ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Vulnerability title: Stored Cross-site Scripting in Oracle Demantra
CVE: CVE-2014-0379
Vendor: Oracle
Product: Demantra
Affected version: 12.2.1
Fixed version: 12.2.3
Reported by: Oliver Gruskovnjak

Details:

The Oracle Demantra application is vulnerable to SQL injection.

An attacker with access to the vulnerable pages could manipulate the
queries being sent to the database, potentially enabling them to extract
sensitive information or modify content within the application.

In this particular instance, exploitation was more difficult as the
results of the attack had to inferred based on the pages returned, often
referred to as "blind" SQL Injection.

Further details at:
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-0379/


Copyright:
Copyright (c) Portcullis Computer Security Limited 2014, All rights
reserved worldwide. Permission is hereby granted for the electronic
redistribution of this information. It is not to be edited or altered in
any way without the express written consent of Portcullis Computer
Security Limited.

Disclaimer:
The information herein contained may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are NO warranties, implied or otherwise, with regard to this information
or its use. Any use of this information is at the user's risk. In no
event shall the author/distributor (Portcullis Computer Security
Limited) be held liable for any damages whatsoever arising out of or in
connection with the use or spread of this information.

[Attachment #5 (text/html)]

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Vulnerability title: Stored Cross-site Scripting in Oracle Demantra<br>
    CVE: CVE-2014-0379<br>
    Vendor: Oracle<br>
    Product: Demantra<br>
    Affected version: 12.2.1<br>
    Fixed version: 12.2.3<br>
    Reported by: Oliver Gruskovnjak<br>
    <br>
    Details:<br>
    <br>
    The Oracle Demantra application is vulnerable to SQL injection.<br>
    <br>
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    An attacker with access to the vulnerable pages could manipulate the
    queries being sent to the database, potentially enabling them to
    extract sensitive information or modify content within the
    application.<br>
    <br>
    In this particular instance, exploitation was more difficult as the
    results of the attack had to inferred based on the pages returned,
    often referred to as &#8220;blind&#8221; SQL Injection.<br>
    <br>
    Further details at:
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    <a
href="https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cv \
e-2014-0379/">https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-0379/</a><br>
  <br>
    <br>
    Copyright:<br>
    Copyright (c) Portcullis Computer Security Limited 2014, All rights
    reserved worldwide. Permission is hereby granted for the electronic
    redistribution of this information. It is not to be edited or
    altered in any way without the express written consent of Portcullis
    Computer Security Limited.<br>
    <br>
    Disclaimer:<br>
    The information herein contained may change without notice. Use of
    this information constitutes acceptance for use in an AS IS
    condition. There are NO warranties, implied or otherwise, with
    regard to this information or its use. Any use of this information
    is at the user's risk. In no event shall the author/distributor
    (Portcullis Computer Security Limited) be held liable for any
    damages whatsoever arising out of or in connection with the use or
    spread of this information.
  </body>
</html>



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic