Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle 9iAS XSQL Servlet文件访问权限绕过漏洞
Vulnerability Description
Oracle 9iAS软件包中包含了XSQL Servlet程序作为开发XML应用的工具,它可以把来自SQL服务器的查询转换成XML格式。 XSQL Servlet实现上存在问题,远程攻击者可能借此得到服务相关的敏感信息。 Servlet没有正确地实施对文件的访问许可权限,远程攻击者可能利用这个漏洞查看系统的配置文件,这个问题与Bugtraq ID为4290的漏洞相似。
CVSS Information
N/A
Vulnerability Type
N/A