source: wwwsecurityfocuscom/bid/1053/info
Oracle Web Listener for NT makes use of various batch files as cgi scripts, which are stored in the /ows-bin/ directory by default
Any of these batch files can be used to run arbitrary commands on the server, simply by appending '?&' and a command to the filename The command will be run at ...