积极预防 及时发现
快速响应 力保恢复
Oracle XSQL serblet 1.0.3.0及其早期版本允许远程攻击者通过使用在xslt样...
发布时间:2001-03-12 信息来源:管理员

CNCVE编号:CNCVE-20010126 CVE编号:CVE-2001-0126 安全级别:高 漏洞中文描述: Oracle XSQL serblet 1.0.3.0及其早期版本允许远程攻击者通过使用在xslt样式表中的xml-stylesheet参数来重新定位XSQL服务器到另一个源地址,从而执行任意java代码。 漏洞英文描述: Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet. 漏洞参考: BUGTRAQ:20010109 Oracle XSQL servlet and xml-stylesheet allow BUGTRAQ:20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误