No account yet?
Home » HSC Research
Hackers Center Security Research Group

 Hackers Center Research Group

 

 
Hackers Center Security Research Group production: advisories, researches, papers, discoveries, discussions



[HSC] Oracle Application Server 10g SSO XSS E-mail
Advisories
Written by Oleg P   
Thursday, 29 January 2009 14:53

OracleAS Portal is a Web-based application for building and deploying portals. It provides a
secure, manageable environment for accessing and interacting with enterprise software services
and information resources. A vulnerability has been identified in Oracle Application Server 10g,
This could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary code
that can be executed by the user's browser in the security context of an affected site. Attackers
can exploit these issues via a web client.


Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Oleg P.

Class: Cross Site Scripting
Remote: Yes
Risk: Medium

Product: Oracle Application Server Portal (OracleAS Portal) 10g
Version: Tested 10.1.3 and Earlier/ Other version may be affrected too.
Vendor: http://www.oracle.com


- Cross Site Scripting -

Login script:

/sso/jsp/login.jsp?site2pstoretoken=XSS


Search Script:

PORTAL&search_type=XSS


PATCHES AND UPDATES:

http://www.oracle.com/technology/deploy/security/alerts.htm

 
[HSC] Oracle Forms Cross site Scripting E-mail
Advisories
Written by Oleg P   
Thursday, 29 January 2009 14:36

Oracle Forms Cross site Scripting in (iFcgi60.exe / f60servlet)

About: Oracle Forms is a tool (somewhat like Visual Basic in appearance, but the code inside is PL/SQL)
which allows a developer to quickly create user-interface applications which access an Oracle database
in a very efficient and tightly-coupled way. It was originally developed to run server-side in character
mode on any Unix box, before Windows existed. It was then ported to Windows to function in a client-server
environment. This could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary
code that can be executed by the user's browser in the security context of an affected site. Attackers can
exploit these issues via a web client.


Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Oleg P.

Class: Cross Site Scripting
Remote: Yes
Risk: Medium

Product: Oracle Forms 6i Servlets
Version: Tested 6i Servlets/ Other version may be affrected too.
(E-Business Suite 11i)

Vendor: http://www.oracle.com


iFcgi60.exe / f60servlet Cross site scripting


ifcgi60.exe?form=XSS


f60servlet?&form=XSS



Open Admin Access:

f60servlet/admin



PATCHES AND UPDATES:

Vendor has been contacted and produced a valid patch addressing the issue:

http://www.oracle.com/technology/deploy/security/alerts.htm


 

 
[HSC] TimeTrex Time and Attendance Cookie Theft E-mail
Advisories
Written by Ethical Hacker   
Thursday, 21 August 2008 17:58
[HSC] TimeTrex Time and Attendance Cookie Theft


TimeTrex allows companies to track and monitor employee attendance accurately in real-time from anywhere

in the world. An attacker may leverage these issues to execute arbitrary script code in the browser of

an unsuspecting user in the context of the affected site. Attacker can tricks the user's computer into

running code which is treated as trustworthy because it appears to belong to the server, allowing the

attacker to obtain a copy of the cookie or perform other operations.



Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Class: Cross Site Scripting
Remote: Yes

Product: TimeTrex
Vendor: http://www.timetrex.com
Version: N/A


Attackers can exploit these issues via a web client.


http://site.com/interface/Login.php?user_name=admin&password=XSS
http://site.com/interface/Login.php?user_name=XSS





Google Dork: TimeTrex Time and Attendance - Secure Login
 
[HSC] SchoolCenter URL Handling Cross Site Scripting Vulnerability E-mail
Advisories
Written by Hackers Center   
Friday, 06 June 2008 04:19

Hackers CenterA vulnerability has been identified in SchoolCenter Software, which could be exploited to conduct cross site scripting attacks. Attackers can run arbitrary code that can be executed by the user's browser in the security context of an affected site. Attackers can exploit these issues via a web client.

Read more...
 
[HSC] XEROX DocuShare URL XSS Injection Vulnerabilities E-mail
Advisories
Written by Hackers Center   
Thursday, 29 May 2008 20:04

HSCXerox DocuShare is a flexible Web-based content management solution that brings greater productivity to every knowledge worker. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Read more...
 
[HSC] MegaBBS ASP Forum Cross-Site Scripting E-mail
Advisories
Written by Hackers Center   
Sunday, 20 January 2008 17:33
[HSC] MegaBBS ASP Forum Cross-Site Scripting


MegaBBS is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Read more...
 
[HSC] IProber Invalid Validation & Information Disclosure E-mail
Advisories
Written by Hackers Center   
Thursday, 10 January 2008 20:16
Read more...
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Page 1 of 16

Security Services by HSC