CVE-2009-1968
Oracle 10g Secure Enterprise Search - 'search_p_groups' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.
La vulnerabilidad no especificada en el componente Secure Enterprise Search en Database de Oracle versión 10.1.8.3, permite a los atacantes remotos afectar a la integridad por medio de vectores desconocidos. NOTA: la información anterior fue obtenida de la CPU de julio de 2009. Oracle no ha comentado sobre las afirmaciones de un investigador establecido de que se trata de cross-site scripting (XSS) por medio del parámetro search_p_groups en el archivo search/query/search.
Oracle Secure Enterprise Search (SES) version 10.1.8.2.0 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-06-08 CVE Reserved
- 2009-06-14 First Exploit
- 2009-07-14 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2009-07/0110.html | Mailing List | |
http://dsecrg.com/pages/vul/show.php?id=125 | X_refsource_misc | |
http://osvdb.org/55892 | Vdb Entry | |
http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html | X_refsource_confirm | |
http://www.securityfocus.com/bid/35681 | Vdb Entry | |
http://www.securitytracker.com/id?1022560 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51754 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33082 | 2009-06-14 |
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2009/1900 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35776 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.1.8.3 Search vendor "Oracle" for product "Database Server" and version "10.1.8.3" | - |
Affected
|