CVE-2007-0222
https://notcve.org/view.php?id=CVE-2007-0222
Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter. NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined. Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293). Una vulnerabilidad de salto de directorio en el componente del lado del servidor del servidor EmChartBean para Oracle Application Server 10g permite a los atacantes remotos leer archivos arbitrarios por medio de vectores desconocidos, probablemente secuencias de "\.." en el parámetro beanId. NOTA: esto es probablemente un duplicado de otro CVE que Oracle abordó en CPU en Enero de 2007, pero debido a la falta de detalles por Oracle, no está claro con qué BugID está asociado este problema, por lo que no se puede determinar el otro CVE. • http://secunia.com/advisories/23794 http://securitytracker.com/id?1017522 http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html http://www.securityfocus.com/archive/1/457105/100/0/threaded http://www.securityfocus.com/archive/1/458657/100/0/threaded http://www.securityfocus.com/bid/22027 http://www.securityfocus.com/bid/22083 •
CVE-2006-6699
https://notcve.org/view.php?id=CVE-2006-6699
Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter to (1) calendarDialog.jsp or (2) fred.jsp. NOTE: the calendar.jsp vector is covered by CVE-2006-6697. Múltiples vulnerabilidades de inyección SRLF en Oracle Portal 9.0.2 y posiblemente otras versiones permiten a un atacante remoto inyectar cabeceras HTTP de su elección y conducir respuestas HTTP diviendo los ataques a través de secuencias CRLF en el parámetro enc a (1) calendarDialog.jsp o (2) fred.jsp. NOTA: el vector calendar.jsp está cubierto por CVE-2006-6697. • http://www.securityfocus.com/archive/1/455106/100/0/threaded •
CVE-2006-6697 – Oracle Portal 9.0.2 - Calendar.jsp Multiple HTTP Response Splitting Vulnerabilities
https://notcve.org/view.php?id=CVE-2006-6697
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter. Vulnerabilidad de inyección de CRLF en webapp/jsp/calendar.jsp en Oracle Portal 10g y anteriores, incluyendo 9.0.2, permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y llevar a cabo ataques de fragmentación de respuestas HTTP mediante secuencias CRLF en el parámetro enc, posiblemente involucrando codificación iso-8859-1. • https://www.exploit-db.com/exploits/29301 http://marc.info/?l=full-disclosure&m=116664018702238&w=2 http://marc.info/?l=full-disclosure&m=116666155824901&w=2 http://secunia.com/advisories/23461 http://securityreason.com/securityalert/2057 http://www.securityfocus.com/archive/1/454945/100/0/threaded http://www.securityfocus.com/archive/1/454965/100/0/threaded http://www.securityfocus.com/archive/1/455106/100/0/threaded http://www.securityfocus.com/bid/21686 http:// •
CVE-2006-5366
https://notcve.org/view.php?id=CVE-2006-5366
Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and remote attack vectors related to (1) Oracle Containers for J2EE, aka Vuln# OC4J01, and (2) Oracle Process Mgmt & Notification, aka OPMN01. Múltiples vulnerabilidades no especificadas en Oracle Collaboration Suite 9.0.4.2 tienen impacto y vectores de ataque remotos desconocidos relacionados con (1) Oracle Containers para J2EE, también conocido como Vuln# OC4J01, y (2) Oracle Process Mgmt & Notification, también conocido como OPMN01. • http://secunia.com/advisories/22396 http://securitytracker.com/id?1017077 http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html http://www.securityfocus.com/archive/1/449711/100/0/threaded http://www.securityfocus.com/bid/20588 http://www.us-cert.gov/cas/techalerts/TA06-291A.html http://www.vupen.com/english/advisories/2006/4065 •
CVE-2006-5354
https://notcve.org/view.php?id=CVE-2006-5354
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06. Vulnerabilidad no especificada en Oracle HTTP Server 9.2.0.7 y 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, y 10.1.3.0, Oracle Collaboration Suite 9.0.4.2 and 10.1.2, y Oracle E-Business Suite y Applications 11.5.10CU2 tiene impacto y vectores de ataque remotos desconocidos, también conocido como Vuln# OHS06. • http://secunia.com/advisories/22396 http://securitytracker.com/id?1017077 http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html http://www.securityfocus.com/archive/1/449711/100/0/threaded http://www.securityfocus.com/bid/20588 http://www.us-cert.gov/cas/techalerts/TA06-291A.html http://www.vupen.com/english/advisories/2006/4065 •