RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

看板Bugtraq作者時間15年前 (2010/10/14 05:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/6 (看更多)
>Hmm... maybe difficult to verify, since I did not post a PoC test. >Maybe a kind Oracle admin could point me to a patched fcgi-bin/echo? >Funny if any such existed: an admin careful to keep patches up-to-date, bu= t >careless in not following security recommendations to remove... >Maybe, contact me off-list so I can provide PoC? If you are going to give PoC code to anyone who asks for it, why not just p= ost it? It will be made public anyway. Or you could apply the patch your= self and test on your own and communicate any vulnerabilities that my persi= st to Oracle first. t
文章代碼(AID): #1CjXuE0D (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #1CjXuE0D (Bugtraq)