Oracle Application Server 9i Webcache - Arbitrary File Corruption

Related Vulnerabilities: CVE-2005-1382  
Publish Date: 28 Apr 2005


Oracle Application Server 9i Webcache is prone to an arbitrary file corruption vulnerability.

The issue exists becaue dangerous characters are not removed from a certain parameter value, allowing an attacker to construct a URI that contains an absolute path to any target file.

If this URI is followed by a user with sufficient privileges, garbage data is appended to the end of the specified file.