Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-9314 PoC — Oracle iPlanet Web Server 注入漏洞

Source
Associated Vulnerability
Title:Oracle iPlanet Web Server 注入漏洞 (CVE-2020-9314)
Description:Oracle iPlanet Web Server(OiWS)是美国甲骨文(Oracle)公司的一款主要用于中型和大型业务应用程序的Web服务器。 Oracle OiWS 7.0.x版本中的管理控制台存在注入漏洞。攻击者可借助‘productNameSrc’参数利用该漏洞实施钓鱼攻击或社会工程攻击。
Description
Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516.
File Snapshot

id: CVE-2020-9314 info: name: Oracle iPlanet Web Server 7.0.x - Image Injection author: Dhiyane ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.