CVE-2002-1089

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:6.0.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:6.0.8.19:*:*:*:*:*:*:*

History

20 Nov 2024, 23:40

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2002-07/0203.html - Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2002-07/0203.html - Vendor Advisory
References () http://www.iss.net/security_center/static/9628.php - () http://www.iss.net/security_center/static/9628.php -
References () http://www.securityfocus.com/bid/5262 - () http://www.securityfocus.com/bid/5262 -

Information

Published : 2002-10-04 04:00

Updated : 2024-11-20 23:40


NVD link : CVE-2002-1089

Mitre link : CVE-2002-1089

CVE.ORG link : CVE-2002-1089


JSON object : View

Products Affected

oracle

  • reports
  • application_server