Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Application Server Portal绕过认证漏洞
Vulnerability Description
Oracle Application Server Portal(OracleAS Portal)是基于Web的应用程序,用于构建和部署portal。 OracleAS Portal在处理访问认证时存在漏洞,如果远程攻击者在提交的HTTP请求头中添加了特制的cookie值的话,就可以绕过对/dav_portal/portal/目录的基本认证保护,访问dav_portal内容。
CVSS Information
N/A
Vulnerability Type
N/A