Description
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
Affected products
- oracle / application_server4.0 – 4.0
Exploits & proofs of concept
- exploit-dbOracle Web Listener 4.0.x - for NT Batch Fileby Cerberus Security Team
Updated 47m ago · 8 sources