|
 Hackers Center Security Research Group production: advisories, researches, papers, discoveries, discussions
|
|
Advisories
|
|
Written by Oleg P
|
|
Thursday, 29 January 2009 14:53 |
|
OracleAS Portal is a Web-based application for building and deploying portals. It provides a secure, manageable environment for accessing and interacting with enterprise software services and information resources. A vulnerability has been identified in Oracle Application Server 10g, This could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary code that can be executed by the user's browser in the security context of an affected site. Attackers can exploit these issues via a web client.
Hackers Center Security Group (http://www.hackerscenter.com) Credit: Oleg P.
Class: Cross Site Scripting Remote: Yes Risk: Medium
Product: Oracle Application Server Portal (OracleAS Portal) 10g Version: Tested 10.1.3 and Earlier/ Other version may be affrected too. Vendor: http://www.oracle.com
- Cross Site Scripting -
Login script:
/sso/jsp/login.jsp?site2pstoretoken=XSS
Search Script:
PORTAL&search_type=XSS
PATCHES AND UPDATES:
http://www.oracle.com/technology/deploy/security/alerts.htm
|
|
|
Advisories
|
|
Written by Oleg P
|
|
Thursday, 29 January 2009 14:36 |
|
Oracle Forms Cross site Scripting in (iFcgi60.exe / f60servlet)
About: Oracle Forms is a tool (somewhat like Visual Basic in appearance, but the code inside is PL/SQL) which allows a developer to quickly create user-interface applications which access an Oracle database in a very efficient and tightly-coupled way. It was originally developed to run server-side in character mode on any Unix box, before Windows existed. It was then ported to Windows to function in a client-server environment. This could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary code that can be executed by the user's browser in the security context of an affected site. Attackers can exploit these issues via a web client.
Hackers Center Security Group (http://www.hackerscenter.com) Credit: Oleg P.
Class: Cross Site Scripting Remote: Yes Risk: Medium
Product: Oracle Forms 6i Servlets Version: Tested 6i Servlets/ Other version may be affrected too. (E-Business Suite 11i)
Vendor: http://www.oracle.com
iFcgi60.exe / f60servlet Cross site scripting
ifcgi60.exe?form=XSS
f60servlet?&form=XSS
Open Admin Access:
f60servlet/admin
PATCHES AND UPDATES: Vendor has been contacted and produced a valid patch addressing the issue:
http://www.oracle.com/technology/deploy/security/alerts.htm
|
|
Advisories
|
|
Written by Ethical Hacker
|
|
Thursday, 21 August 2008 17:58 |
[HSC] TimeTrex Time and Attendance Cookie Theft

TimeTrex allows companies to track and monitor employee attendance accurately in real-time from anywhere
in the world. An attacker may leverage these issues to execute arbitrary script code in the browser of
an unsuspecting user in the context of the affected site. Attacker can tricks the user's computer into
running code which is treated as trustworthy because it appears to belong to the server, allowing the
attacker to obtain a copy of the cookie or perform other operations.
Hackers Center Security Group (http://www.hackerscenter.com) Credit: Doz
Class: Cross Site Scripting Remote: Yes
Product: TimeTrex Vendor: http://www.timetrex.com Version: N/A
Attackers can exploit these issues via a web client.
http://site.com/interface/Login.php?user_name=admin&password=XSS http://site.com/interface/Login.php?user_name=XSS
Google Dork: TimeTrex Time and Attendance - Secure Login |
|
Advisories
|
|
Written by Hackers Center
|
|
Friday, 06 June 2008 04:19 |
|
A vulnerability has been identified in SchoolCenter Software, which could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary code that can be executed by the user's browser in the security context of an affected site. Attackers can exploit these issues via a web client.
|
|
Read more...
|
|
Advisories
|
|
Written by Hackers Center
|
|
Thursday, 29 May 2008 20:04 |
|
Xerox DocuShare is a flexible Web-based content management solution that brings greater productivity to every knowledge worker. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
|
|
Read more...
|
|
Advisories
|
|
Written by Hackers Center
|
|
Sunday, 20 January 2008 17:33 |
[HSC] MegaBBS ASP Forum Cross-Site Scripting
MegaBBS is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
|
|
Read more...
|
|
Advisories
|
|
Written by Hackers Center
|
|
Thursday, 10 January 2008 20:16 |
|
|
|
Read more...
|
|
|
|
|
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
|
|
Page 1 of 16 |