3.5
CVSSv2

CVE-2007-0275

Published: 17/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle database server 10.1.0.5

oracle database server 10.2.0.3

oracle application server 10.1.2.0.2

oracle application server 10.1.2.2

oracle database server 9.2.0.8

oracle e-business suite 11.5.10.2

oracle application server 9.0.4.3

oracle collaboration suite 10.1.2

Exploits

Oracle HTTP Server for Oracle Application Server 10g version 101202 suffers from a cross site scripting vulnerability ...