CVE-2007-2119
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.
Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en boundary_rules.jsp en el Administration Front End para Oracle Enterprise (Ultra) Search, utilizado en Database Server 9.2.0.8, 10.1.0.5, y 10.2.0.2, y en Application Server 9.0.4.3, 10.1.2.0.2, y 10.1.2.2.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro EXTYPE, también conocido como SES01.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-04-18 CVE Reserved
- 2007-04-18 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html | X_refsource_confirm | |
http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html | X_refsource_misc | |
http://www.red-database-security.com/advisory/oracle_css_ses.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/466156/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/23532 | Vdb Entry | |
http://www.securitytracker.com/id?1017927 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-108A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2007/1426 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/466329/100/200/threaded | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Application Server Search vendor "Oracle" for product "Application Server" | 9.0.4.3 Search vendor "Oracle" for product "Application Server" and version "9.0.4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Server Search vendor "Oracle" for product "Application Server" | 10.1.2.0.2 Search vendor "Oracle" for product "Application Server" and version "10.1.2.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Application Server Search vendor "Oracle" for product "Application Server" | 10.1.2.2 Search vendor "Oracle" for product "Application Server" and version "10.1.2.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 9.2.0.8 Search vendor "Oracle" for product "Database Server" and version "9.2.0.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.1.0.5 Search vendor "Oracle" for product "Database Server" and version "10.1.0.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.2 Search vendor "Oracle" for product "Database Server" and version "10.2.0.2" | - |
Affected
|