[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Oracle Portal 10g HTTP Response Splitting
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Re: Oracle Portal 10g HTTP Response Splitting
- From: majororacle@xxxxxxxxx
- Date: 21 Dec 2006 21:18:53 -0000
This also occurs in Portal 9.0.2 in the file calendar.jsp, calendarDialog.jsp,
and fred.jsp, all of which are under the $ORACLE_HOME/j2ee directory in various
locations. The offending code is
String enc = request.getParameter("enc");
if ((enc == null) || "".equals(enc))
response.setContentType("text/html");
else
response.setContentType("text/html;charset=" + enc);
which can be commented out as follows:
// String enc = request.getParameter("enc");
// if ((enc == null) || "".equals(enc))
response.setContentType("text/html");
// else
// response.setContentType("text/html;charset=" + enc);