[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo
- To: "paul.szabo@xxxxxxxxxxxxx" <paul.szabo@xxxxxxxxxxxxx>, "bugtraq@xxxxxxxxxxxxxxxxx" <bugtraq@xxxxxxxxxxxxxxxxx>, "full-disclosure@xxxxxxxxxxxxxxxxx" <full-disclosure@xxxxxxxxxxxxxxxxx>
- Subject: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo
- From: "Thor (Hammer of God)" <thor@xxxxxxxxxxxxxxx>
- Date: Wed, 13 Oct 2010 20:42:16 +0000
>Hmm... maybe difficult to verify, since I did not post a PoC test.
>Maybe a kind Oracle admin could point me to a patched fcgi-bin/echo?
>Funny if any such existed: an admin careful to keep patches up-to-date, but
>careless in not following security recommendations to remove...
>Maybe, contact me off-list so I can provide PoC?
If you are going to give PoC code to anyone who asks for it, why not just post
it? It will be made public anyway. Or you could apply the patch yourself and
test on your own and communicate any vulnerabilities that my persist to Oracle
first.
t