Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2009-07/0110.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51754 | vdb entry |
http://secunia.com/advisories/35776 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2009/1900 | patch vendor advisory vdb entry |
http://osvdb.org/55892 | vdb entry |
http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html | |
http://dsecrg.com/pages/vul/show.php?id=125 | |
http://www.securitytracker.com/id?1022560 | vdb entry |
http://www.securityfocus.com/bid/35681 | vdb entry |