|
Products
Repscan 2008
PLSQL-Scanner
Hedgehog Enterprise
Checkpwd (free)
Services
Oracle Audit / Hardening
Security Training
Consulting
Information
Published Alerts
Upcoming Alerts
Patch Information
Whitepaper
Presentations
Oracle Fact Sheets
Exploits
Videos
Scripts
News & Events
Events
News
Company
Blog
Contact
People
Partner
Impressum
Sitemap
Search
|
Cross Site Scripting in iSQLPlus action parameter
Details
The action parameter of the iSQL*plus login mask is vulnerable against Cross Site Scripting.
Example
http://server/isqlplus?action=<script>alert('CSS')</script>
Patch Information
Apply the latest Oracle patchsets.
© 2005 by Red-Database-Security GmbH - last update 02-nov-2005
|
Hardening Oracle Application Server
- Change Default Password in the Infrastructure Database
- Protect the TNS Listener
- Remove Demo Applications / Pages
- Disable Reports Diagnosis Pages
- Disable Forms Query/Where
- Stop unneeded Components
|